CVE-2026-92438
8.8 HIGHPublished 2026-09-22 · Updated 2026-09-22
AI risk analysis
- Summary
- The flaw allows unauthenticated users to inject malicious code into form submissions, which could then be executed in the browser of an admin user reviewing the submission, leading to potential remote code execution.
- Exploitability
- Exploitation is relatively straightforward as it requires submitting a form with malicious content, which can then be executed by an admin viewing the submission. Precondition is that the admin has access to the submission edit screen.
- Blast radius
- If exploited, the impact could be severe, as it allows for remote code execution in the context of an admin user, potentially leading to full control over the affected WordPress site.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to Ninja Forms version 3.15.4 or later.
rcewebwordpressformadmin
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
The Ninja Forms WordPress plugin 3.15.3 does not escape submitted form field values before outputting them on the submission edit screen in the admin area, which could allow unauthenticated users to submit values through a public form that then execute in the browser of any high-privileged user who reviews the submission.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-79
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-73546PoC
- HIGHCVE-2026-86609
- MEDIUMCVE-2026-15941
- HIGHCVE-2026-15979
- CRITICALCVE-2026-16618
- CRITICALCVE-2026-16940
- CRITICALCVE-2026-19658
- CRITICALCVE-2026-75031PoC
Related by shared AI tags and CWE weakness class. Browse the full archive.