{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-94504", "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599", "state": "PUBLISHED", "assignerShortName": "Wordfence", "dateReserved": "2026-09-21T18:14:35.313Z", "datePublished": "2026-09-22T06:39:41.379Z", "dateUpdated": "2026-09-22T14:13:49.472Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599", "shortName": "Wordfence", "dateUpdated": "2026-09-22T06:39:41.379Z" }, "affected": [ { "vendor": "kstover", "product": "Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder", "versions": [ { "version": "0", "status": "affected", "lessThanOrEqual": "3.15.3", "versionType": "semver" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin." } ], "title": "Ninja Forms – The Contact Form Builder That Grows With You <= 3.15.3 - Stored Cross-Site Scripting", "references": [ { "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/c599a562-5218-4b37-bcf7-0e82008a4e68?source=cve" }, { "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Fields/Textarea.php#L35" }, { "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/trunk/includes/Fields/Textarea.php#L35" }, { "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Templates/admin-metabox-sub-fields.html.php#L23" }, { "url": "https://plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Database/Models/Submission.php#L205" }, { "url": "https://plugins.trac.wordpress.org/changeset?reponame=&new=3705719%40ninja-forms%2Ftags%2F3.15.4&old=3685242%40ninja-forms%2Ftags%2F3.15.3" } ], "problemTypes": [ { "descriptions": [ { "lang": "en", "description": "CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')", "cweId": "CWE-79", "type": "CWE" } ] } ], "metrics": [ { "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N", "baseScore": 7.2, "baseSeverity": "HIGH" } } ], "credits": [ { "lang": "en", "type": "finder", "value": "Hippolyte Quéré (Hippie) (Hippie)" } ], "timeline": [ { "time": "2026-09-11T20:28:47.000Z", "lang": "en", "value": "Vendor Notified" }, { "time": "2026-09-21T18:15:56.000Z", "lang": "en", "value": "Disclosed" } ] }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-09-22T14:13:42.051303Z", "id": "CVE-2026-94504", "options": [ { "Exploitation": "none" }, { "Automatable": "yes" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-09-22T14:13:49.472Z" } } ] } }