Sceawere

Vulnerability Detail

CVE-2026-90438UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Ninja Forms Stored XSS Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.2
Creation Date
17h ago
Vendor
kstover
Product
Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder
Attack Type
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Attack Complexity
LOW

Narrative and Response

Description

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Paragraph Text (RTE) Field Submission in all versions up to, and including, 3.15.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This is only exploitable when the targeted Paragraph Text field has the Rich Text Editor (RTE) option enabled.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.2",
  "pubDate": "2026-10-02T06:16:42.050Z",
  "pubdate": "2026-10-02T06:16:42.050Z",
  "executiveSummary": "The Ninja Forms WordPress plugin is susceptible to a Stored Cross-Site Scripting (XSS) vulnerability due to improper input sanitization and output escaping within the Paragraph Text (RTE) field submission mechanism.\nThe vulnerability permits unauthenticated remote attackers to inject malicious JavaScript payloads into affected form fields.\nThese payloads are subsequently executed in the context of a victim's browser session whenever they access a page containing the injected content.\nThe flaw specifically impacts installations where the Rich Text Editor (RTE) functionality is enabled for Paragraph Text fields in versions up to and including 3.15.4.\nSuccessful exploitation allows attackers to perform unauthorized actions on behalf of the victim, such as session hijacking, data exfiltration, or unauthorized content modification.\nGiven the nature of the injection, this vulnerability poses a critical risk to site integrity and administrative security, as it does not require authentication to trigger the initial payload delivery.",
  "technicalDetails": "The vulnerability resides in the processing of user-supplied data submitted via the Paragraph Text field when the Rich Text Editor (RTE) option is active. The root cause is a failure in the plugin's internal sanitization routines and a corresponding lack of contextual output escaping when rendering the form submissions in the WordPress backend or frontend.\nThe attack flow begins when an unauthenticated attacker identifies a public-facing form created with Ninja Forms that utilizes the Paragraph Text field with RTE enabled. The attacker submits a crafted HTTP POST request containing a malicious payload (e.g., <script>alert(document.cookie)</script>) within the input field. Because the plugin does not adequately sanitize or strip executable tags from this input, the payload is stored directly in the database.\nOnce the malicious data is persisted, the plugin renders this data as part of a web page—typically within a dashboard view or an administrative report—without performing output escaping. When an authenticated user, such as an administrator, views the compromised record, the browser interprets the stored payload as legitimate script content and executes it within the security context of the user's active session.\nBecause the payload executes in the victim's browser, the attacker can leverage the victim's session cookies to bypass CSRF protections, perform administrative tasks, or redirect users to malicious domains. The vulnerability is triggered automatically upon rendering the injected data, requiring no further interaction from the victim once they navigate to the page where the content is displayed.\nThis issue affects all versions of the Ninja Forms plugin up to and including 3.15.4. The exposure is global, as the submission process is public by design, allowing any remote user to inject arbitrary JavaScript that executes with the privileges of whoever views the report. The lack of validation on the RTE field specifically allows HTML tags to be processed by the browser, rendering the application defenseless against persistent cross-site scripting attacks."
}
CVE-2026-90438: Ninja Forms Stored XSS Vulnerability (HIGH Severity, CVSS: 7.2) | Sceawere