Impact
This vulnerability allows an attacker to inject arbitrary JavaScript when a paragraph field with Rich Text Editor enabled is submitted to the Ninja Forms plugin. The input is not sanitized or escaped before being stored, so the malicious code is persisted and executed in any user’s browser when the page is viewed. As a result, attackers can steal session data, deface content, or perform further attacks on behalf of the victim.
Affected Systems
All installations of the Ninja Forms – Contact Form Builder with Calculators, Quizzes, Signatures & AI Form Builder plugin running version 3.15.4 or earlier are affected. The attack does not require user authentication and exploits the rich text paragraph field functionality.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.2, indicating a high severity. The EPSS score is unavailable, and the issue is not listed in the CISA KEV catalog. An attacker can leverage the public form interface to submit malicious scripts; no special access or privileges are necessary beyond being able to submit a form. If a target site displays stored submissions to visitors, the exploit will trigger in any user's browser who views the affected page.
OpenCVE Enrichment