CVE-2026-90438 Overview
CVE-2026-90438 is a stored Cross-Site Scripting (XSS) vulnerability [CWE-79] in the Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress. The flaw affects all versions up to and including 3.15.4. It stems from insufficient input sanitization and output escaping on Paragraph Text fields that have the Rich Text Editor (RTE) option enabled. Unauthenticated attackers can submit crafted form content that stores arbitrary JavaScript. The payload executes when a user, typically an administrator reviewing submissions, loads a page containing the injected content.
Critical Impact
Unauthenticated attackers can store JavaScript payloads via public contact forms, enabling session hijacking, administrative account takeover, and persistent site compromise when administrators review submissions.
Affected Products
- Ninja Forms plugin for WordPress, all versions through 3.15.4
- WordPress sites using Paragraph Text fields with the Rich Text Editor (RTE) option enabled
- Fixed in Ninja Forms 3.15.5
Discovery Timeline
- 2026-10-02 - CVE-2026-90438 published to NVD
- 2026-10-03 - Last updated in NVD database
Technical Details for CVE-2026-90438
Vulnerability Analysis
The vulnerability resides in the submission handling pipeline of the Ninja Forms plugin. When a Paragraph Text field has the Rich Text Editor option enabled, the plugin accepts HTML content from the user to preserve formatting. The submitted value flows through the AJAX submission controller at includes/AJAX/Controllers/Submission.php and is persisted via includes/Database/Models/Submission.php. The stored value is later rendered to administrators in the submissions view without sufficient escaping. An unauthenticated remote attacker can submit a form containing script-carrying HTML. The payload is stored server-side and executes in the browser of any user who opens the submission.
Root Cause
The root cause is a failure to properly sanitize RTE field input on write and to escape it on output. The plugin trusts the richer HTML markup allowed by the RTE path but does not enforce an allow-list that strips event handler attributes or script-equivalent constructs. Because submission requires no authentication, the attack surface is the public form endpoint.
Attack Vector
Exploitation requires only network access to a form on the target site. The attacker submits a Paragraph Text (RTE) field value containing an HTML construct that executes JavaScript when rendered. Review of the submission in the WordPress admin dashboard triggers the payload in the administrator's authenticated session. Impact includes cookie theft, forced administrative actions through authenticated requests, and insertion of persistent backdoors into site content or plugins.
See the vendor fix in the Ninja Forms Submission Controller Changeset and the tag diff between 3.15.4 and 3.15.5 for the specific sanitization changes applied.
Detection Methods for CVE-2026-90438
Indicators of Compromise
- Form submission records containing HTML tags such as <script>, <iframe>, <svg>, or inline event handlers (onerror, onload, onclick) within Paragraph Text field values.
- Unexpected outbound requests from administrator browsers to attacker-controlled domains shortly after viewing the Ninja Forms submissions page.
- New or modified administrator accounts, plugin installations, or theme file changes immediately following access to the submissions dashboard.
Detection Strategies
- Query the nf3_submissions and related post-meta tables for stored submission values matching HTML tag or JavaScript patterns.
- Review web server access logs for POST requests to admin-ajax.php with the nf_ajax_submit action containing suspicious payload markers.
- Correlate wp-admin page views of Ninja Forms submissions with concurrent outbound traffic from the viewing user's workstation.
Monitoring Recommendations
- Enable WordPress audit logging to record form submission content, plugin changes, and administrator session activity.
- Alert on creation of WordPress users with administrator role outside of change windows.
- Monitor file integrity for wp-content/plugins and wp-content/themes directories to catch post-exploitation web shell writes.
How to Mitigate CVE-2026-90438
Immediate Actions Required
- Upgrade the Ninja Forms plugin to version 3.15.5 or later on every WordPress site in the environment.
- Audit all existing form submissions for stored HTML or JavaScript payloads and purge malicious entries before administrators next view them.
- Rotate credentials for any WordPress administrator who viewed submissions while the vulnerable version was installed.
Patch Information
The vendor addressed the vulnerability in Ninja Forms 3.15.5. The fix modifies submission handling to properly sanitize RTE field input. Review the Wordfence Vulnerability Report and the upstream changeset for details.
Workarounds
- Disable the Rich Text Editor (RTE) option on all Paragraph Text fields until the plugin is upgraded, which removes the exploitable code path.
- Deploy a web application firewall rule to block form submissions containing <script, javascript:, or event handler attributes in Ninja Forms POST parameters.
- Restrict access to the WordPress admin dashboard by IP allow-list to limit which workstations can trigger stored payloads during review.
# Example WP-CLI command to confirm Ninja Forms is upgraded to a fixed version
wp plugin update ninja-forms --version=3.15.5
wp plugin get ninja-forms --field=version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.