Stored Script Vulnerability in Ninja Forms by WP Ninjas
CVE-2026-94504
7.2HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 September 2026
What is CVE-2026-94504?
Ninja Forms version 3.15.3 contains a vulnerability where non-RTE textarea values are stored without proper HTML encoding in the legacy submission editor. This flaw allows an attacker to inject malicious scripts that execute when an Administrator accesses the submission URL. The attack could lead to unauthorized actions within the WordPress admin interface, posing a significant risk to site integrity.
Affected Version(s)
Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder 0 <= 3.15.3