PT-2026-96652 · WordPress · Ninja Forms
CVE-2026-92438
·
Published
2026-09-22
·
Updated
2026-09-28
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ninja Forms WordPress plugin version 3.15.3
Description
Insufficient escaping of submitted form field values occurs before they are displayed on the submission edit screen within the admin area. This allows unauthenticated users to submit malicious values via a public form that execute in the browser of high-privileged users who review the submission. This is a stored cross-site scripting (XSS) issue, where a script is permanently stored on the server and executed when a user views the affected page.
Recommendations
Update Ninja Forms WordPress plugin to a version newer than 3.15.3.
Exploit
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ninja Forms