AI analysis
Ninja Forms 3.15.3 stores values submitted through anonymous (no login required) non-rich-text textarea fields and renders them in the legacy submission editor without safe HTML encoding, allowing an attacker to break out of the textarea with injected script. When an administrator opens the direct submission URL for that entry in wp-admin, the script executes in the WordPress admin origin, enabling session hijacking, unauthorized administrative actions, or creation of a backdoor admin account. Any WordPress site running this version with public forms whose submissions are viewed in the legacy editor is affected. There is no known public proof-of-concept, no CISA KEV entry, and no observed in-the-wild exploitation, but the attack only requires submitting a crafted form entry and getting an admin to view it (CVSS 3.1: 7.2, AV:N/AC:L/PR:N).
What to do: Upgrade Ninja Forms from 3.15.3 to the latest patched release from WordPress.org as soon as possible. Review stored submissions for HTML/script breakout in textarea fields, and audit for unexpected administrator accounts, changed settings, or newly installed plugins/themes that could indicate a hijacked admin session. As defense in depth, restrict submission viewing to trusted roles and treat links to specific submission URLs from untrusted sources with caution.
Affected
| Saturday Drive Ninja Forms (WordPress plugin) | 3.15.3 |
Estimated exposure
large≈800,000+ sites potentially running the plugin (order of 10^5–10^6), with the submissions-enabled subset plausibly in the hundreds of thousands — Ninja Forms is one of the most-installed WordPress form plugins, with roughly 800,000+ active installs reported in the WordPress.org plugin directory, scaled down for sites that disable submissions or do not use the legacy submission…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Ninja Forms 3.15.3 stores an anonymous non-RTE textarea value and renders it without safe HTML encoding in the legacy submission editor. An attacker can break out of the textarea with stored script. When an Administrator opens the attacker-known direct submission URL, the script runs in the WordPress admin origin.