{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3aninja_formsninja_formswordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ninja_forms:ninja_forms:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-94504"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ninja Forms (\u003c= 3.15.3)"],"_cs_severities":["high"],"_cs_tags":["xss","web-vulnerability","wordpress"],"_cs_type":"advisory","_cs_vendors":["Ninja Forms"],"content_html":"\u003cp\u003eCVE-2026-94504 is a security vulnerability in the Ninja Forms plugin (version 3.15.3) that stems from improper input sanitization of anonymous non-RTE (Rich Text Editor) textarea fields. The plugin stores user-provided input in these fields and fails to perform adequate HTML encoding when rendering the data within the legacy submission editor interface. An attacker can supply malicious JavaScript payloads within these textarea inputs. When a site administrator accesses the specific direct submission URL associated with the malicious entry, the injected script executes within the context of the WordPress admin origin. This flaw allows attackers to perform unauthorized actions or gain access to sensitive information by leveraging the trust associated with the administrator's authenticated session.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in Stored Cross-Site Scripting (XSS), which can lead to session hijacking, unauthorized administrative actions, or the unauthorized modification of site content. This vulnerability specifically impacts WordPress environments where Ninja Forms 3.15.3 is installed and utilizes the legacy submission editor.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade the Ninja Forms plugin to a patched version beyond 3.15.3 immediately.\u003c/li\u003e\n\u003cli\u003eImplement a strong Content Security Policy (CSP) to mitigate the execution of unauthorized scripts in the WordPress admin dashboard.\u003c/li\u003e\n\u003cli\u003eAudit existing submission entries for suspicious script tags or obfuscated JavaScript payloads.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-22T08:34:19Z","date_published":"2026-09-22T08:34:19Z","id":"https://feed.craftedsignal.io/briefs/2026-09-ninja-forms-xss/","summary":"CVE-2026-94504 describes a stored cross-site scripting vulnerability in Ninja Forms version 3.15.3, allowing attackers to execute arbitrary scripts in an administrator's browser session via the legacy submission editor.","title":"Stored Cross-Site Scripting in Ninja Forms Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-ninja-forms-xss/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:ninja_forms:ninja_forms:*:*:*:*:*:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}