<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Ninja Forms – The Contact Form Builder That Grows With You (&lt;= 3.15.4) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ninja-forms--the-contact-form-builder-that-grows-with-you--3.15.4/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 06:23:00 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ninja-forms--the-contact-form-builder-that-grows-with-you--3.15.4/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Stored XSS in Ninja Forms WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-ninja-forms-xss/</link><pubDate>Fri, 02 Oct 2026 06:23:00 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ninja-forms-xss/</guid><description>The Ninja Forms WordPress plugin versions 3.15.4 and earlier contain a stored Cross-Site Scripting vulnerability allowing unauthenticated attackers to inject malicious scripts via Paragraph Text fields with Rich Text Editor enabled.</description><content:encoded><![CDATA[<p>The Ninja Forms - The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting (XSS) due to insufficient input sanitization and output escaping within its Paragraph Text field handling. This vulnerability, identified as CVE-2026-90438, affects all versions up to and including 3.15.4. Unauthenticated attackers can exploit this by submitting specially crafted malicious scripts through forms where the Paragraph Text field has the Rich Text Editor (RTE) option enabled. Once submitted, the malicious payload is stored by the application and executes in the browser context of any user, such as an administrator, who views the submitted form data in the WordPress dashboard. This allows for session hijacking, credential theft, or unauthorized administrative actions.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to execute arbitrary JavaScript in the context of the WordPress administrative session. This can lead to full site compromise, unauthorized configuration changes, or the injection of further malicious content, directly impacting the security posture of any WordPress site utilizing the affected versions of the plugin.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Update the Ninja Forms - The Contact Form Builder That Grows With You plugin to the latest version immediately to remediate CVE-2026-90438. Prioritize identifying and auditing any forms currently using the Paragraph Text field with the Rich Text Editor (RTE) option enabled to check for potential existing payloads.</p>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-vulnerability</category><category>wordpress</category><category>xss</category><category>cve-2026-90438</category></item></channel></rss>