• PoC PUBLIC

CVE-2026-94504: stored xss in kstover Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder

An unauthenticated attacker can store JavaScript in Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder that executes when an administrator views the legacy submission editor; this is tracked as CVE-2026-94504. The vulnerability affects Ninja Forms 3.15.3 and earlier in the 3.x branch and arises from an anonymous non-RTE textarea value rendered without safe HTML encoding. An attacker only needs the ability to submit a crafted form entry and an administrator to open the attacker-controlled submission URL.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
7.2HIGH
EPSS
0.00412
CWE
CWE-79
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code exists for this flaw, so restrict admin access to submission pages immediately and treat exposed sites as high priority to remediate or mitigate.

What is CVE-2026-94504?

An unauthenticated attacker can store JavaScript in Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder that executes when an administrator views the legacy submission editor; this is tracked as CVE-2026-94504. The vulnerability affects Ninja Forms 3.15.3 and earlier in the 3.x branch and arises from an anonymous non-RTE textarea value rendered without safe HTML encoding. An attacker only needs the ability to submit a crafted form entry and an administrator to open the attacker-controlled submission URL. The weakness is classified as CWE-79 (Cross-site Scripting).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N

Which versions of kstover Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder are affected?

BRANCHAFFECTEDFIXED
3.x3.15.3 and earlier

Is CVE-2026-94504 being exploited?

Public exploit code is available.

How to fix CVE-2026-94504

  1. Restrict access to the WordPress admin and legacy submission editor to trusted IPs or VPN users.
  2. Disable or block direct submission URLs and untrusted submission viewing where possible.
  3. Monitor admin access and submission logs for suspicious entries and administrator views of direct submission links.
  4. Follow vendor guidance and apply a vendor-supplied patch as soon as a fixed version is released.

Frequently asked questions

Is CVE-2026-94504 being actively exploited?

Public exploit code is available for CVE-2026-94504, indicating a realistic risk of active exploitation.

Which Ninja Forms versions are affected by CVE-2026-94504?

Ninja Forms 3.x is affected; specifically versions 3.15.3 and earlier are listed as vulnerable.

Is there a patch for CVE-2026-94504?

There is no fixed version listed for CVE-2026-94504; administrators should follow vendor guidance and apply updates when a patch is released.

Does CVE-2026-94504 require authentication?

No. The issue involves an anonymous non-RTE textarea submission that can be stored without authentication and runs when an administrator opens the submission URL.

References