Skip to main content
Vulnerability Database/CVE-2026-94504

CVE-2026-94504: Ninja Forms XSS Vulnerability

CVE-2026-94504 is a stored XSS flaw in Ninja Forms 3.15.3 that allows attackers to inject malicious scripts through textarea fields. When administrators view submissions, the script executes in WordPress admin context. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-94504 Overview

CVE-2026-94504 is a stored cross-site scripting (XSS) vulnerability [CWE-79] in the Ninja Forms WordPress plugin version 3.15.3. The plugin stores anonymous non-RTE textarea submissions and renders them in the legacy submission editor without safe HTML encoding. An unauthenticated attacker can submit a textarea payload that breaks out of the textarea element and injects script. When an Administrator opens the direct submission URL, the injected script executes in the WordPress admin origin.

Critical Impact

Unauthenticated attackers can inject persistent JavaScript that executes with Administrator context in the WordPress admin interface, enabling account takeover and site compromise.

Affected Products

  • Ninja Forms plugin for WordPress, version 3.15.3
  • Legacy submission editor component (admin-metabox-sub-fields.html.php)
  • Textarea field handler (includes/Fields/Textarea.php)

Discovery Timeline

  • 2026-09-22 - CVE-2026-94504 published to the National Vulnerability Database
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-94504

Vulnerability Analysis

The vulnerability resides in how Ninja Forms 3.15.3 handles anonymous submissions from non-rich-text-editor (non-RTE) textarea fields. The plugin persists the raw submitted value through the Submission model and later renders it in the administrative submission editor without applying HTML entity encoding. Because the rendering context is an HTML <textarea> element inside a WordPress admin page, an attacker can supply a payload containing a closing </textarea> tag followed by a <script> block. The script executes when an Administrator views the submission.

Execution in the admin origin gives the attacker access to nonces, session cookies not marked HttpOnly, and any REST or AJAX endpoints authorized to the viewing Administrator. This can be leveraged to create rogue administrator accounts, install plugins, or modify site content.

Root Cause

The root cause is missing output encoding in the legacy admin metabox template. The template emits stored submission values inside a <textarea> without escaping HTML-sensitive characters such as <, >, and &. Because the textarea field code path does not sanitize the input before storage and the render layer does not encode on output, attacker-controlled markup survives end-to-end. The relevant code paths are includes/Database/Models/Submission.php, includes/Fields/Textarea.php, and includes/Templates/admin-metabox-sub-fields.html.php.

Attack Vector

The attack requires no authentication and no user interaction from the submitter. An attacker submits a crafted textarea value through any public Ninja Forms form on the target site. The payload is stored persistently in the submissions table. When an Administrator subsequently opens the attacker-known direct submission URL in the WordPress admin, the injected script runs in the admin origin. See the Wordfence Vulnerability Report and the Ninja Forms Textarea Field Code for the affected component.

Detection Methods for CVE-2026-94504

Indicators of Compromise

  • Ninja Forms submissions containing </textarea>, <script, onerror=, onload=, or javascript: substrings in textarea field values.
  • Unexpected WordPress administrator account creations, plugin installations, or option changes following an admin session that viewed a submission.
  • HTTP POST requests to Ninja Forms submission endpoints (admin-ajax.php with action=nf_ajax_submit) from unauthenticated sources containing HTML tag payloads.

Detection Strategies

  • Query the wp_nf3_submissions and related postmeta tables for stored field values containing HTML tags or script constructs.
  • Inspect web server access logs for POST bodies to Ninja Forms endpoints containing tag-breakout sequences targeting the textarea field.
  • Monitor WordPress audit logs for administrator-level actions occurring immediately after a submission view event.

Monitoring Recommendations

  • Alert on new WordPress user creation with the administrator role outside change windows.
  • Log and review browser Content Security Policy (CSP) violation reports from /wp-admin/ pages.
  • Track version drift on the Ninja Forms plugin across managed WordPress deployments to identify hosts still on 3.15.3 or earlier.

How to Mitigate CVE-2026-94504

Immediate Actions Required

  • Upgrade Ninja Forms to version 3.15.4 or later, which contains the fix referenced in the Ninja Forms Version Change Log.
  • Audit existing submissions for stored payloads and purge or sanitize any entries containing HTML or script markup before administrators view them.
  • Rotate WordPress administrator credentials and invalidate active sessions on any site where a suspicious submission was viewed.

Patch Information

The vendor addressed the issue in Ninja Forms 3.15.4. The changeset updates the textarea field handling and admin submission rendering path to prevent stored HTML from executing in the admin context. Review the Ninja Forms Textarea Field Code (Trunk) for the current sanitization logic.

Workarounds

  • Deactivate the Ninja Forms plugin until the upgrade to 3.15.4 or later can be completed.
  • Place a web application firewall (WAF) rule in front of /wp-admin/admin-ajax.php to block requests where textarea fields contain <script, </textarea>, or event-handler attributes.
  • Restrict access to the WordPress admin interface by IP allowlist so that only trusted networks can render stored submissions.
bash
# Configuration example: update the Ninja Forms plugin via WP-CLI
wp plugin update ninja-forms --version=3.15.4
wp plugin list --name=ninja-forms --fields=name,status,version

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.