CVE-2026-94504 Overview
CVE-2026-94504 is a stored cross-site scripting (XSS) vulnerability [CWE-79] in the Ninja Forms WordPress plugin version 3.15.3. The plugin stores anonymous non-RTE textarea submissions and renders them in the legacy submission editor without safe HTML encoding. An unauthenticated attacker can submit a textarea payload that breaks out of the textarea element and injects script. When an Administrator opens the direct submission URL, the injected script executes in the WordPress admin origin.
Critical Impact
Unauthenticated attackers can inject persistent JavaScript that executes with Administrator context in the WordPress admin interface, enabling account takeover and site compromise.
Affected Products
- Ninja Forms plugin for WordPress, version 3.15.3
- Legacy submission editor component (admin-metabox-sub-fields.html.php)
- Textarea field handler (includes/Fields/Textarea.php)
Discovery Timeline
- 2026-09-22 - CVE-2026-94504 published to the National Vulnerability Database
- 2026-09-22 - Last updated in NVD database
Technical Details for CVE-2026-94504
Vulnerability Analysis
The vulnerability resides in how Ninja Forms 3.15.3 handles anonymous submissions from non-rich-text-editor (non-RTE) textarea fields. The plugin persists the raw submitted value through the Submission model and later renders it in the administrative submission editor without applying HTML entity encoding. Because the rendering context is an HTML <textarea> element inside a WordPress admin page, an attacker can supply a payload containing a closing </textarea> tag followed by a <script> block. The script executes when an Administrator views the submission.
Execution in the admin origin gives the attacker access to nonces, session cookies not marked HttpOnly, and any REST or AJAX endpoints authorized to the viewing Administrator. This can be leveraged to create rogue administrator accounts, install plugins, or modify site content.
Root Cause
The root cause is missing output encoding in the legacy admin metabox template. The template emits stored submission values inside a <textarea> without escaping HTML-sensitive characters such as <, >, and &. Because the textarea field code path does not sanitize the input before storage and the render layer does not encode on output, attacker-controlled markup survives end-to-end. The relevant code paths are includes/Database/Models/Submission.php, includes/Fields/Textarea.php, and includes/Templates/admin-metabox-sub-fields.html.php.
Attack Vector
The attack requires no authentication and no user interaction from the submitter. An attacker submits a crafted textarea value through any public Ninja Forms form on the target site. The payload is stored persistently in the submissions table. When an Administrator subsequently opens the attacker-known direct submission URL in the WordPress admin, the injected script runs in the admin origin. See the Wordfence Vulnerability Report and the Ninja Forms Textarea Field Code for the affected component.
Detection Methods for CVE-2026-94504
Indicators of Compromise
- Ninja Forms submissions containing </textarea>, <script, onerror=, onload=, or javascript: substrings in textarea field values.
- Unexpected WordPress administrator account creations, plugin installations, or option changes following an admin session that viewed a submission.
- HTTP POST requests to Ninja Forms submission endpoints (admin-ajax.php with action=nf_ajax_submit) from unauthenticated sources containing HTML tag payloads.
Detection Strategies
- Query the wp_nf3_submissions and related postmeta tables for stored field values containing HTML tags or script constructs.
- Inspect web server access logs for POST bodies to Ninja Forms endpoints containing tag-breakout sequences targeting the textarea field.
- Monitor WordPress audit logs for administrator-level actions occurring immediately after a submission view event.
Monitoring Recommendations
- Alert on new WordPress user creation with the administrator role outside change windows.
- Log and review browser Content Security Policy (CSP) violation reports from /wp-admin/ pages.
- Track version drift on the Ninja Forms plugin across managed WordPress deployments to identify hosts still on 3.15.3 or earlier.
How to Mitigate CVE-2026-94504
Immediate Actions Required
- Upgrade Ninja Forms to version 3.15.4 or later, which contains the fix referenced in the Ninja Forms Version Change Log.
- Audit existing submissions for stored payloads and purge or sanitize any entries containing HTML or script markup before administrators view them.
- Rotate WordPress administrator credentials and invalidate active sessions on any site where a suspicious submission was viewed.
Patch Information
The vendor addressed the issue in Ninja Forms 3.15.4. The changeset updates the textarea field handling and admin submission rendering path to prevent stored HTML from executing in the admin context. Review the Ninja Forms Textarea Field Code (Trunk) for the current sanitization logic.
Workarounds
- Deactivate the Ninja Forms plugin until the upgrade to 3.15.4 or later can be completed.
- Place a web application firewall (WAF) rule in front of /wp-admin/admin-ajax.php to block requests where textarea fields contain <script, </textarea>, or event-handler attributes.
- Restrict access to the WordPress admin interface by IP allowlist so that only trusted networks can render stored submissions.
# Configuration example: update the Ninja Forms plugin via WP-CLI
wp plugin update ninja-forms --version=3.15.4
wp plugin list --name=ninja-forms --fields=name,status,version
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.