Vulnerability in Ninja Forms – The Contact Form Builder That Grows With You — CVE-2026-94504
HighSeverity
—Estimated exploit probability
600,000+ sitesInstalls
3.15.4Fixed in
What to do now
Update Ninja Forms – The Contact Form Builder That Grows With You to 3.15.4 or later.
Affected versions
- Everything up to and including 3.15.3
Affected: Ninja Forms – The Contact Form Builder That Grows With You (plugin, ninja-forms)
What the vulnerability is
Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.