DIRAS TAKE
Urgent: public exploit code exists for this flaw, so restrict admin access to submission pages immediately and treat exposed sites as high priority to remediate or mitigate.
What is CVE-2026-94504?
An unauthenticated attacker can store JavaScript in Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder that executes when an administrator views the legacy submission editor; this is tracked as CVE-2026-94504. The vulnerability affects Ninja Forms 3.15.3 and earlier in the 3.x branch and arises from an anonymous non-RTE textarea value rendered without safe HTML encoding. An attacker only needs the ability to submit a crafted form entry and an administrator to open the attacker-controlled submission URL. The weakness is classified as CWE-79 (Cross-site Scripting).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Which versions of kstover Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 3.x | 3.15.3 and earlier |
Is CVE-2026-94504 being exploited?
Public exploit code is available.
How to fix CVE-2026-94504
- Restrict access to the WordPress admin and legacy submission editor to trusted IPs or VPN users.
- Disable or block direct submission URLs and untrusted submission viewing where possible.
- Monitor admin access and submission logs for suspicious entries and administrator views of direct submission links.
- Follow vendor guidance and apply a vendor-supplied patch as soon as a fixed version is released.
Frequently asked questions
Is CVE-2026-94504 being actively exploited?
Public exploit code is available for CVE-2026-94504, indicating a realistic risk of active exploitation.
Which Ninja Forms versions are affected by CVE-2026-94504?
Ninja Forms 3.x is affected; specifically versions 3.15.3 and earlier are listed as vulnerable.
Is there a patch for CVE-2026-94504?
There is no fixed version listed for CVE-2026-94504; administrators should follow vendor guidance and apply updates when a patch is released.
Does CVE-2026-94504 require authentication?
No. The issue involves an anonymous non-RTE textarea submission that can be stored without authentication and runs when an administrator opens the submission URL.
References
- nvd.nist.gov/vuln/detail/CVE-2026-94504
- cve.org/CVERecord?id=CVE-2026-94504
- wordfence.com/threat-intel/vulnerabilities/id/c599a562-5218-4b37-bcf7-0e82008a4e68?source=cve
- plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Fields/Textarea.php#L35
- plugins.trac.wordpress.org/browser/ninja-forms/trunk/includes/Fields/Textarea.php#L35
- plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Templates/admin-metabox-sub-fields.html.php#L23
- plugins.trac.wordpress.org/browser/ninja-forms/tags/3.15.3/includes/Database/Models/Submission.php#L205
- plugins.trac.wordpress.org/changeset?reponame=&new=3705719%40ninja-forms%2Ftags%2F3.15.4&old=3685242%40ninja-forms%2Ftags%2F3.15.3
- All kstover CVEs on CVE Radar
- CVEs published in September 2026