{"id":"CVE-2026-92438","published":"2026-09-22T07:16:31.220","lastModified":"2026-09-22T19:41:38.447","description":"The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the submission.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwes":["CWE-79"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/eeed1378-2c51-4d38-9dda-4a13ce330b25/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated users to inject malicious code into form submissions, which could then be executed in the browser of an admin user reviewing the submission, leading to potential remote code execution.","exploitability":"Exploitation is relatively straightforward as it requires submitting a form with malicious content, which can then be executed by an admin viewing the submission. Precondition is that the admin has access to the submission edit screen.","blast_radius":"If exploited, the impact could be severe, as it allows for remote code execution in the context of an admin user, potentially leading to full control over the affected WordPress site.","remediation":"Upgrade to Ninja Forms version 3.15.4 or later.","detection":"No reliable host or network indicator is derivable from the published description.","tags":["rce","web","wordpress","form","admin"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-29T09:14:48.200Z"}}