PT-2026-96652 · WordPress · Ninja Forms

CVE-2026-92438

·

Published

2026-09-22

·

Updated

2026-09-28

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ninja Forms WordPress plugin version 3.15.3
Description Insufficient escaping of submitted form field values occurs before they are displayed on the submission edit screen within the admin area. This allows unauthenticated users to submit malicious values via a public form that execute in the browser of high-privileged users who review the submission. This is a stored cross-site scripting (XSS) issue, where a script is permanently stored on the server and executed when a user views the affected page.
Recommendations Update Ninja Forms WordPress plugin to a version newer than 3.15.3.

Exploit

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92438

Affected Products

Ninja Forms