CVE-2026-94504

Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.

  • Published Sep 22, 2026
  • CVSS 7.2 high
  • 0.4% chance of exploitation in the next 30 days (EPSS)
  • A fix is available

Affected software

CVE-2026-94504 at the National Vulnerability Database