CVE-2026-94504: Kstover Ninja Forms – Contact Form Builder With Calculators, Quizzes, Signatures & Ai Form Builder

High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.

Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.

Affected products

  • Kstover Ninja Forms – Contact Form Builder With Calculators, Quizzes, Signatures & Ai Form Builder: up to and including 3.15.3

Published 2026-09-22. Last modified 2026-09-22.