---
id: CVE-2026-94504
title: >-
  Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it
  without safe HTML encoding in the legacy submission editor
summary: >-
  Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it
  without safe HTML encoding in the legacy submission editor. An attacker can
  break out of the textarea with stored script. When an Administrator opens the
  attack…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
vendor: kstover
product: >-
  Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI
  Form Builder
affected:
  - >-
    ninja_forms_contact_form_builder_with_calculators_quizzes_signatures_ai_form_builder
    <= 3.15.3
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:04:55.677'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94504'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Database/Models/Submission.php#L205
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Fields/Textarea.php#L35
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Templates/admin-metabox-sub-fields.html.php#L23
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/ninja-forms/trunk/includes/Fields/Textarea.php#L35
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&new=3705719%40ninja-forms%2Ftags%2F3.15.4&old=3685242%40ninja-forms%2Ftags%2F3.15.3
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/c599a562-5218-4b37-bcf7-0e82008a4e68?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
  - exploit-available
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-22T14:13:42.051303Z'
ingestedAt: '2026-09-22T06:59:42.680Z'
epss: 0.00412
epssPercentile: 0.32789
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/cflowsec/cve-2026-94504'
  checkedAt: '2026-09-26T09:06:06.943Z'
exploitAvailable: true
---

## Overview

Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
