---
id: CVE-2026-92438
title: >-
  The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field
  values before outputting them on the submission edit screen in the admin area,
  which could allow unauthenticated users to submit values through a public form
  th…
summary: >-
  The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field
  values before outputting them on the submission edit screen in the admin area,
  which could allow unauthenticated users to submit values through a public form
  th…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-79
product: Ninja Forms
affected:
  - ninja_forms >= 3.15.3 < 3.15.4
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:41:38.447'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-92438'
references:
  - url: 'https://wpscan.com/vulnerability/eeed1378-2c51-4d38-9dda-4a13ce330b25/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
epss: 0.00347
epssPercentile: 0.25592
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T10:05:25.560794Z'
ingestedAt: '2026-09-22T08:00:27.683Z'
---

## Overview

The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the submission.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
