Ninja Forms was fixed 14 days before Patchstack saw the first attack, and the fix does not clean a hacked site
Ninja Forms 3.15.4 fixed CVE-2026-94504 on 21 September 2026, and Patchstack's first recorded attempt on it is dated 5 October. The update stops new attacks but does not remove a backdoor already planted, and nine Ninja Forms records in 29 days make 'up to date' a harder claim than it sounds.
By Parminder Kumar Sharma · · 16 min read

Fixed on 21 September, first attack seen on 5 October: 14 days
Ninja Forms 3.15.4 was released on 21 September 2026 with the fix for CVE-2026-94504, a stored cross-site scripting (XSS) flaw that Wordfence, the CVE's assigner, scores 7.2. Patchstack, a WordPress security firm, says it first recorded an attempt to exploit that flaw on 5 October. That is 14 days (derived), the same 14 days that Cyber Essentials v3.3 allows for a fix where the vendor gives no severity or the score is 7 or above. The NCSC's five-day target for internet-facing software ended on 26 September, nine days before that attempt. BleepingComputer reported the campaign on 6 October.
What that does not establish. It does not say how many sites were hit, or that any attempt succeeded on a Ninja Forms site: Patchstack reports attempts, calls exploitation volume "limited in our telemetry", and says a site where the script ran should be treated as potentially compromised. It does not say a site on 3.15.4 or later is clean: Patchstack and BleepingComputer both say an update stops further attacks but removes no backdoor already planted. It does not make 3.15.4 the version to aim for: a newer flaw, CVE-2026-90438, affects 3.15.4 and is fixed in 3.15.5 (28 September), and no source we read reports that one exploited. And it does not show how many sites are exposed, although a statistic that looks as if it does is in circulation; the install section below shows what it can carry.
What the campaign does, at the level a defender needs
Patchstack describes one JavaScript implant delivered through stored XSS flaws in two unrelated plugins: Ninja Forms (more than 500,000 installs) and WPC Product Bundles for WooCommerce (CVE-2026-93836, fixed in 8.6.7, more than 30,000). The attacker needs no account. The hostile content arrives as an ordinary public form entry, sits in the database, and runs when an administrator opens it in the admin screens, using that administrator's logged-in session. BleepingComputer says both flaws "require an authenticated session". Wordfence, Patchstack and the CVE record describe the attacker as unauthenticated and the victim as an administrator, so this briefing follows them.
On Patchstack's account the script then uses that session to install a plugin posing as an image-thumbnail helper (BleepingComputer gives the name as WP Smart Thumbnails, from "MediaPress Labs"), create an administrator, and leave four ways back in: a visible administrator; a second one hidden from the Users screen; a secret login link that signs in as the site's oldest administrator; and a file manager that needs no login. Removing the vulnerable plugin, or the fake one, closes none of the last three, Patchstack says. The file manager runs no commands but can write files, so it can bring in more code. What the operators did on any compromised site is not stated.
The attack dates are Patchstack's alone. It says the attack domain was registered on 1 October, nine days after the 22 September disclosure (it says "roughly ten"; the dates give nine), and that its first request is timed 10:39 UTC on 4 October, against the other plugin. We could not check those against a second source. Patchstack and Wordfence both sell protection, which is a reason to check what they publish, not to doubt it. Where we could check, their dates and fixed versions match CVE.org and the vendor's changelog.
What is stated, and what is not
Position at about 11:40 BST on 7 October 2026. Stated: Patchstack's report of 6 October, BleepingComputer's report, the Wordfence, CVE.org and NVD records, the vendor's changelog. Not stated: what those sources do not say, which we checked for.
- Item
- First attack
- Stated
- Patchstack: first payload sighting 4 October (other plugin), the same payload through Ninja Forms on 5 October.
- Not stated
- Anything earlier or outside Patchstack's telemetry. Wordfence's entry carried no attack count when read.
- Item
- How many sites
- Stated
- Volume "limited in our telemetry".
- Not stated
- Any count of compromised sites, successful attempts or UK sites.
- Item
- Versions
- Stated
- Wordfence and the CVE record: all versions up to 3.15.3. Fixed in 3.15.4 (21 September, changelog).
- Not stated
- Whether the oldest branches (3.6, 3.8) behave the same. No source tested them.
- Item
- What the victim does
- Stated
- A logged-in administrator opens the stored submission.
- Not stated
- How many sites have an administrator who does, or whether an update neutralises entries stored before it.
- Item
- After the foothold
- Stated
- Four ways back in, one visible. An update does not clean a hit site.
- Not stated
- What the operators did, or whether form data was read or taken.
- Item
- Severity
- Stated
- Wordfence (the CNA) 7.2. CISA-ADP's SSVC entry of 22 September: exploitation none, automatable yes, technical impact partial.
- Not stated
- Any vendor rating. Its changelog says "Security Enhancements" and no more.
- Item
- CISA KEV
- Stated
- Not listed at catalogue version 2026.10.04.
- Not stated
- Whether it will be. Absence proves nothing: CVE-2026-0740 has been exploited since 6 April and is not listed.
- Item
- Who
- Stated
- Same payload and server across two plugins; BleepingComputer says that indicates one threat actor.
- Not stated
- An identity, or that no other group uses the same flaws.
| Item | Stated | Not stated |
|---|---|---|
| First attack | Patchstack: first payload sighting 4 October (other plugin), the same payload through Ninja Forms on 5 October. | Anything earlier or outside Patchstack's telemetry. Wordfence's entry carried no attack count when read. |
| How many sites | Volume "limited in our telemetry". | Any count of compromised sites, successful attempts or UK sites. |
| Versions | Wordfence and the CVE record: all versions up to 3.15.3. Fixed in 3.15.4 (21 September, changelog). | Whether the oldest branches (3.6, 3.8) behave the same. No source tested them. |
| What the victim does | A logged-in administrator opens the stored submission. | How many sites have an administrator who does, or whether an update neutralises entries stored before it. |
| After the foothold | Four ways back in, one visible. An update does not clean a hit site. | What the operators did, or whether form data was read or taken. |
| Severity | Wordfence (the CNA) 7.2. CISA-ADP's SSVC entry of 22 September: exploitation none, automatable yes, technical impact partial. | Any vendor rating. Its changelog says "Security Enhancements" and no more. |
| CISA KEV | Not listed at catalogue version 2026.10.04. | Whether it will be. Absence proves nothing: CVE-2026-0740 has been exploited since 6 April and is not listed. |
| Who | Same payload and server across two plugins; BleepingComputer says that indicates one threat actor. | An identity, or that no other group uses the same flaws. |
The dates, to scale
One brand, four flaws, two codebases
Ninja Forms is a free plugin on WordPress.org and a catalogue of paid add-ons sold by its publisher, Saturday Drive. "Ninja Forms is being exploited" has been true of two of them, six months apart, and a summary of this story that we checked joins figures from both.
Wordfence Intelligence entries and blog, Patchstack, BleepingComputer, vendor changelogs. Read 7 October 2026.
- Flaw
- CVE-2026-94504. Free plugin, up to 3.15.3, fixed 3.15.4 (21 Sep).
- What it is
- Unauthenticated stored XSS, fires when an administrator opens a submission. 7.2.
- Exploitation reported
- Patchstack: first seen 5 October 2026.
- Flaw
- CVE-2026-90438. Free plugin, up to 3.15.4, fixed 3.15.5 (28 Sep).
- What it is
- Unauthenticated stored XSS, only where a Paragraph Text field has the rich text option on. 7.2. Entry dated 1 October.
- Exploitation reported
- None reported in the sources we read.
- Flaw
- CVE-2026-0740. File Uploads add-on, up to 3.3.26, fixed 3.3.27.
- What it is
- Unauthenticated arbitrary file upload, can lead to remote code execution. 9.8. Disclosed 6 April 2026.
- Exploitation reported
- Wordfence: from 6 April; over 118,600 blocked by 16 April. BleepingComputer, 7 April: over 3,600 blocked in 24 hours.
- Flaw
- CVE-2026-92820. File Uploads add-on, up to 3.3.34, fixed 3.3.35 per Wordfence.
- What it is
- Unauthenticated arbitrary file read, write and deletion, only with the Amazon S3 upload action. 8.1. Entry dated 1 October.
- Exploitation reported
- None reported in the sources we read.
| Flaw | What it is | Exploitation reported |
|---|---|---|
| CVE-2026-94504. Free plugin, up to 3.15.3, fixed 3.15.4 (21 Sep). | Unauthenticated stored XSS, fires when an administrator opens a submission. 7.2. | Patchstack: first seen 5 October 2026. |
| CVE-2026-90438. Free plugin, up to 3.15.4, fixed 3.15.5 (28 Sep). | Unauthenticated stored XSS, only where a Paragraph Text field has the rich text option on. 7.2. Entry dated 1 October. | None reported in the sources we read. |
| CVE-2026-0740. File Uploads add-on, up to 3.3.26, fixed 3.3.27. | Unauthenticated arbitrary file upload, can lead to remote code execution. 9.8. Disclosed 6 April 2026. | Wordfence: from 6 April; over 118,600 blocked by 16 April. BleepingComputer, 7 April: over 3,600 blocked in 24 hours. |
| CVE-2026-92820. File Uploads add-on, up to 3.3.34, fixed 3.3.35 per Wordfence. | Unauthenticated arbitrary file read, write and deletion, only with the Amazon S3 upload action. 8.1. Entry dated 1 October. | None reported in the sources we read. |
Three figures that travel with the story belong elsewhere. "Over 600,000" appears in BleepingComputer's April article as downloads, not installs, and matches no other number we read: WordPress.org shows 500,000+ active installations and Wordfence's database 63,836,263 downloads. "More than 3,600 attacks in 24 hours" is Wordfence's count against the add-on flaw around 7 April. And CVE-2026-0740 is 184 days old (derived) and not part of this campaign. The vendor's changelog dates its complete fix to 16 March, Wordfence and BleepingComputer say 19 March; this briefing follows the vendor's page.
The friendly name. "A form plugin" sounds like a contact form. A file-upload field is an entry point that takes files from the internet, and the add-on that provides it is a second codebase under the same brand. A green "up to date" on the free plugin says nothing about it. The two are linked, too: Wordfence says CVE-2026-19769, in the free plugin up to 3.15.1, can be exploited only when the File Uploads add-on is active. Nor is the add-on's size settled: Wordfence's April post says about 50,000 active installations, its database 57,944, and BleepingComputer 90,000 customers.
Updates are not automatic by default, and add-ons need a licence. WordPress's documentation says core updates itself by default and plugins only "in special cases". Since WordPress 5.5 an administrator can switch auto-updates on or off for each plugin. For the add-ons, the vendor's licensing page says each comes with a one-year licence covering updates, with the key entered on the site to receive them, and its subscriptions page says "You will be unable to receive support or updates for expired licenses." The NCSC's guidance says to make sure you have the required licences. The File Uploads page showed a starting price of $49 a year on 7 October.
A security line is not guaranteed. The vendor's File Uploads changelog dates 3.3.35 to 5 October and lists bug fixes and enhancements only. Wordfence's entry for CVE-2026-92820, published on 1 October and updated on 2 October, names 3.3.35 as the fix. We cannot reconcile those dates from public pages. A team waiting for a release note that says "security" would not have seen this one.
Nine entries in 29 days, from three assigners
Wordfence's database dates nine Ninja Forms entries between 2 September and 1 October 2026, 29 days end to end (derived). Seven are labelled unauthenticated. Counting from 4 September, as one summary does, gives eight by 1 October and seven by 28 September, the day 3.15.5 was released. Databases disagree: Patchstack's own page lists ten entries from 4 September to about 2 October, and we did not map them one to one. The nine CVE records behind Wordfence's entries came from three assigners: Wordfence four, WPScan four, Patchstack one.
Dates are Wordfence database dates (CVE.org can differ by a day); release dates from the WordPress.org changelog. Scores from CVE.org and NVD (assigner first) and the Wordfence database (second). Read 7 October 2026.
- Entry
- CVE-2026-80438, 2 Sep. Needs a custom role. Information exposure.
- Fixed in
- 3.15.2 (31 Aug)
- Score: assigner, then Wordfence
- CISA-ADP 5.9 (in NVD); Wordfence 3.1
- Entry
- CVE-2026-19769, 4 Sep. Unauthenticated XSS, only with the File Uploads add-on active.
- Fixed in
- 3.15.2 (31 Aug)
- Score: assigner, then Wordfence
- Wordfence 7.2, both
- Entry
- CVE-2026-80437, 4 Sep. Unauthenticated shortcode execution.
- Fixed in
- 3.15.2 (31 Aug)
- Score: assigner, then Wordfence
- WPScan 4.8; Wordfence 6.5
- Entry
- CVE-2026-11363, 8 Sep. Administrator only. PHP object injection.
- Fixed in
- 3.14.7 (18 Jun)
- Score: assigner, then Wordfence
- Wordfence 6.6, both
- Entry
- CVE-2026-94504, 21 Sep. Unauthenticated XSS. The exploited one.
- Fixed in
- 3.15.4 (21 Sep)
- Score: assigner, then Wordfence
- Wordfence 7.2, both
- Entry
- CVE-2026-91827, 22 Sep. Unauthenticated PHP object injection.
- Fixed in
- 3.15.4 (21 Sep)
- Score: assigner, then Wordfence
- WPScan 7.5; Wordfence 8.1
- Entry
- CVE-2026-92438, 22 Sep. Unauthenticated XSS.
- Fixed in
- 3.15.4 (21 Sep)
- Score: assigner, then Wordfence
- WPScan 8.8; Wordfence 7.2
- Entry
- CVE-2026-95515, 23 Sep. Unauthenticated XSS.
- Fixed in
- 3.15.4 (21 Sep)
- Score: assigner, then Wordfence
- Patchstack 7.1; Wordfence 7.2
- Entry
- CVE-2026-90438, 1 Oct. Unauthenticated XSS, rich text option only.
- Fixed in
- 3.15.5 (28 Sep)
- Score: assigner, then Wordfence
- Wordfence 7.2, both
| Entry | Fixed in | Score: assigner, then Wordfence |
|---|---|---|
| CVE-2026-80438, 2 Sep. Needs a custom role. Information exposure. | 3.15.2 (31 Aug) | CISA-ADP 5.9 (in NVD); Wordfence 3.1 |
| CVE-2026-19769, 4 Sep. Unauthenticated XSS, only with the File Uploads add-on active. | 3.15.2 (31 Aug) | Wordfence 7.2, both |
| CVE-2026-80437, 4 Sep. Unauthenticated shortcode execution. | 3.15.2 (31 Aug) | WPScan 4.8; Wordfence 6.5 |
| CVE-2026-11363, 8 Sep. Administrator only. PHP object injection. | 3.14.7 (18 Jun) | Wordfence 6.6, both |
| CVE-2026-94504, 21 Sep. Unauthenticated XSS. The exploited one. | 3.15.4 (21 Sep) | Wordfence 7.2, both |
| CVE-2026-91827, 22 Sep. Unauthenticated PHP object injection. | 3.15.4 (21 Sep) | WPScan 7.5; Wordfence 8.1 |
| CVE-2026-92438, 22 Sep. Unauthenticated XSS. | 3.15.4 (21 Sep) | WPScan 8.8; Wordfence 7.2 |
| CVE-2026-95515, 23 Sep. Unauthenticated XSS. | 3.15.4 (21 Sep) | Patchstack 7.1; Wordfence 7.2 |
| CVE-2026-90438, 1 Oct. Unauthenticated XSS, rich text option only. | 3.15.5 (28 Sep) | Wordfence 7.2, both |
Three things follow. First, 3.15.4 closed four unauthenticated flaws at once, and 3.15.5 closed another a week later. Every release from 3.15.1 to 3.15.5 carries a "Security Enhancements" heading in the changelog: five releases in 35 days, with gaps of 7, 7, 14 and 7 days.
Second, scores differ by up to 2.8 points between assigners, and no difference crosses the line of 7 that Cyber Essentials uses, but the number plainly depends on who calculates it. The vendor calculates none: its disclosure policy tells reporters to submit confirmed issues to the WPScan database and request a CVE ID. Wordfence's vector for CVE-2026-94504 records no user interaction, though an administrator has to open the submission. A score of 7.2 does not tell you that someone must look.
Third, fixes pre-date their entries. CVE-2026-11363 was fixed on 18 June and published on 8 September. A site that waits for the database entry is waiting for the wrong signal.
What the install statistics say, and what they cannot
WordPress.org's Ninja Forms page shows version 3.15.5, "500,000+" active installations and, in its Advanced View, the share of installs by version bucket: 3.15 at 50.0%, 3.14 at 13.5%, 3.8 at 6.6%, 3.6 at 7.2%, other 22.7%. The stats API gives the unrounded figures, which sum to 100.00 (3.15 at 49.96%). So 50.04% of installs report a version older than 3.15 (derived). Read at the floor of the band, that is about 250,200 sites (derived); the real figure is higher by an amount the page does not give.
What that does not establish. The 3.15 bucket spans 3.15.0 to 3.15.5 and is not split, so the share on the fixed 3.15.4 and 3.15.5 is not stated. The older buckets sit inside Wordfence's affected range (all versions up to 3.15.3), though no source tested the old branches. No row says how many sites an attacker can reach: the attack also needs an administrator who opens stored submissions (our inference: a site where nobody does is less exposed to this chain, not safe from the others). The page gives no definition of "active installation", and a count of sites is not a count of sites at risk.
One more number. WordPress.org's daily download count was 162,365 on 22 September, the day after 3.15.4, and 131,048 on 29 September, the day after 3.15.5, against a derived mean of about 8,500 a day from 10 to 20 September. After 3.15.3 it was 173,213 on 8 September. That fits automatic updates (our inference) and shows the update path works for many sites. It says nothing about those that did not take it.
The UK reading: three clocks, and who owns each
Cyber Essentials. Requirements for IT Infrastructure v3.3 (April 2026) says software in scope must be updated "within 14 days" of release where the update fixes flaws the vendor calls critical or high, addresses a CVSS v3 base score of 7 or above, or where the vendor gives "no details of the level" of what it fixes. Saturday Drive's changelog gives no level, only "Security Enhancements". Our reading is that the third condition applies the 14 days to every Ninja Forms release carrying such an entry, whatever the scores, and that scores of 7.2 and above also meet the second if an assessor accepts a score the vendor did not assign. The text does not say whose CVSS counts. That is our reading, not an assessor's ruling. On it, a monthly patch cycle could not have met the requirement at the release rate of the five weeks to 28 September.
The same document says cloud services holding your services cannot be excluded from scope, that the applicant "is always responsible for ensuring all controls are implemented" even where a provider does the work, and that accounts your organisation owns stay in scope when a supplier or managed service provider uses them. For an agency-run site, the 14 days is your obligation and the agency's task.
The NCSC. Its update-by-default guidance (version 2.1, reviewed 1 May 2026) gives five days for internet-facing services and software, seven for operating systems and applications, 14 for internal ones. For a vulnerability being exploited it says to "investigate your exposure and check for signs of compromise before applying any update", because brief exposure can still have been enough. Its website guidance, written for large organisations and the public sector, says a CMS user must install security updates when the vendor releases them, and that this includes themes and plugins. Our earlier briefings on what to search for after a WordPress exploit and on a backdoor that is not gone when cleaned make the same point from other cases.
The ICO. Its guide says a notifiable breach must be reported "not later than 72 hours" after you become aware, that you notify if a risk to people's rights and freedoms is likely, and that a decision not to report should be justified and documented. A processor must tell you "without undue delay", and the contract should say how. A site whose forms collect names, addresses or messages stores personal data. Whether an attacker who held an administrator session read it is what the sources do not say, so the first job on a hit site is to establish what was reachable. Your clock runs from your own awareness.
What to do, in the order worth doing it
Our judgement on the order, not a standard. Step 2 comes before the update because the NCSC advises checking first and because an update does not undo a compromise.
Take this with you
If your organisation, charity, school, council or agency runs WordPress with Ninja Forms
- List every WordPress site your organisation owns or pays for, including ones an agency or freelancer runs and old campaign sites, with its form plugin, every add-on and the version of each. A site nobody lists is a site nobody patches.
- For each site that ran Ninja Forms 3.15.3 or earlier at any point since 22 September, take a snapshot or backup so evidence survives, then update to 3.15.5, not just 3.15.4.
- On those sites, look for the signs in general terms: administrators the database holds that the Users screen does not show; a plugin you did not install that poses as an image or thumbnail helper (this campaign used the name WP Smart Thumbnails); unfamiliar entries in the Must-Use section of the Plugins screen, which hosts also use legitimately; a login link or file manager you did not set up; server or proxy logs mentioning the attack domain, written defanged as imgcdn1[.]com; stored submissions containing markup or links to unfamiliar domains. File dates are not reliable, because Patchstack says the campaign backdates its files.
- If you find any of it, remove the accounts and plugins, rotate every administrator password and the WordPress authentication salts, treat the oldest administrator's password as compromised, and prefer replacing or rebuilding the site from a known-good backup to a clean-up, as the NCSC advises for a compromised internet-facing system.
- Check that every paid add-on has a valid licence with its key entered on the site, or updates do not arrive. Update each add-on; File Uploads was at 3.3.35 on 7 October.
- Remove the File Uploads add-on, and any upload field, from forms that do not need to take files. Where one does, keep it current and treat everything uploaded as untrusted.
- Ask your host or agency in writing whether a web application firewall rule covers Ninja Forms and its add-ons, and who applies updates. A rule is a stopgap, not a patch, and Patchstack notes most attack sources were Tor exit nodes, so blocking addresses does not last.
- Switch on automatic updates for the plugin where your change control allows, and set a weekly look: five security-bearing releases in the 35 days to 28 September means a monthly cycle will always be behind.
- Test a restore from a backup older than 21 September. A backup you have never restored is a hope.
- If a hit site held personal data from forms, decide and write down whether the breach is notifiable. Tell the ICO within 72 hours of becoming aware if a risk to people is likely, and ask your agency or host, as processor, to tell you without undue delay.
The question that exposes the gap
Your agency's last report says every plugin is up to date. Does it list the add-ons and the date each licence expires, and does it show the administrator accounts the database holds, not only the ones the Users screen will admit to?
Key facts
Sources
- PrimaryFour ways back in: the WordPress XSS campaign that hides its own admin account, 6 October 2026, read in full in a browser at about 11:10 BST on 7 October 2026. The primary source for the campaign, the first sightings (4 and 5 October), the four persistence routes, the domain registration date and the update guidance. Patchstack sells protection, so its telemetry is its own and uncorroborated.Patchstackaccessed 2026-10-07
- PrimaryWordfence Intelligence listing for the Ninja Forms plugin, read at about 11:11 BST on 7 October 2026: 88 entries, nine dated 2 September to 1 October 2026, with scores, researchers' dates and the 500,000 active installs figure. Each of the nine entries was also read: affected and fixed versions, vector, dates.Wordfenceaccessed 2026-10-07
- PrimaryWordfence Intelligence entry for CVE-2026-94504: unauthenticated stored XSS, up to 3.15.3, fixed in 3.15.4, 7.2 with vector, published 21 September, updated 24 September 2026. No attack count on the entry when read.Wordfenceaccessed 2026-10-07
- PrimaryWordfence Intelligence entry for CVE-2026-90438: unauthenticated stored XSS via Paragraph Text rich text field, up to 3.15.4, fixed in 3.15.5, published 1 October 2026.Wordfenceaccessed 2026-10-07
- PrimaryWordfence Intelligence listing for the Ninja Forms File Uploads add-on, read at about 11:17 BST on 7 October 2026: six entries dated in 2026, 57,944 active installs on a record last updated 20 April 2026. The entries for CVE-2026-92820, CVE-2026-13369, CVE-2026-81773, CVE-2026-12557 and CVE-2026-57784 were also read.Wordfenceaccessed 2026-10-07
- PrimaryWordfence Intelligence entry for CVE-2026-92820 in the File Uploads add-on: arbitrary file operations via the Amazon S3 upload flow, up to 3.3.34, fixed in 3.3.35, 8.1, published 1 October, updated 2 October 2026.Wordfenceaccessed 2026-10-07
- PrimaryAttackers Actively Exploiting Critical Vulnerability in Ninja Forms File Upload Plugin, 16 April 2026. The primary source for CVE-2026-0740: disclosure on 6 April, same-day exploitation, over 118,600 attempts blocked, mass exploitation 9 to 13 April, about 50,000 installations, firewall rule dates.Wordfenceaccessed 2026-10-07
- PrimaryNinja Forms plugin page, read at about 11:12 BST on 7 October 2026: version 3.15.5, 500,000+ active installations, last updated 1 week ago, tested up to 7.1.3.WordPress.orgaccessed 2026-10-07
- PrimaryNinja Forms Advanced View, read at about 11:18 BST on 7 October 2026: the active versions chart data, other 22.7%, 3.6 7.2%, 3.8 6.6%, 3.14 13.5%, 3.15 50.0%.WordPress.orgaccessed 2026-10-07
- PrimaryWordPress.org plugin stats API for the version split, read at 11:12 BST on 7 October 2026: unrounded figures, 3.15 49.96, 3.14 13.53, 3.6 7.24, 3.8 6.6, other 22.67, summing to 100.WordPress.orgaccessed 2026-10-07
- PrimaryWordPress.org daily download counts for Ninja Forms, read at 11:18 BST on 7 October 2026; used for the spikes after each release.WordPress.orgaccessed 2026-10-07
- PrimaryWordPress.org plugin information API, read at 11:12 BST on 7 October 2026: the readme changelog with release dates 3.15.0 (12 August) to 3.15.5 (28 September 2026) and the Security Enhancements headings.WordPress.orgaccessed 2026-10-07
- PrimaryCVE record for CVE-2026-94504 read through the CVE Services API at about 11:14 BST on 7 October 2026: assigner Wordfence, reserved 21 September, published 22 September 2026, affected up to 3.15.3, CNA score 7.2. The same API was used for the other eight Ninja Forms records and CVE-2026-0740.CVE Programaccessed 2026-10-07
- PrimaryNVD record for CVE-2026-94504 read at about 11:14 BST on 7 October 2026: status Deferred, the CNA's 7.2 marked Secondary, and the CISA-ADP SSVC entry of 22 September (exploitation none, automatable yes, technical impact partial). The same API was used for the other Ninja Forms CVEs.NIST NVDaccessed 2026-10-07
- PrimaryKnown Exploited Vulnerabilities catalogue, version 2026.10.04, released 4 October 2026 at 18:52 UTC, 1,734 entries, read at about 11:15 BST on 7 October 2026. None of the Ninja Forms CVEs checked was listed.CISAaccessed 2026-10-07
- PrimaryNinja Forms File Uploads add-on page and changelog, read in a browser on 7 October 2026: version 3.3.35, release dates 3.3.25 to 3.3.35, the yearly licence and starting price. Used for the vendor's dates, which differ from Wordfence's by three days for 3.3.27.Saturday Drive (Ninja Forms)accessed 2026-10-07
- PrimaryAdd-on Licensing and Updates, read on 7 October 2026: each add-on has a one-year licence covering updates, with the key entered on the site.Saturday Drive (Ninja Forms)accessed 2026-10-07
- PrimaryManaging Subscriptions, read on 7 October 2026: updates are unavailable for expired licences.Saturday Drive (Ninja Forms)accessed 2026-10-07
- PrimaryResponsible Security Disclosure Policy, read on 7 October 2026: confirmed issues are sent to the WPScan database for a CVE ID. No security advisory for the October releases was found on the vendor's site.Saturday Drive (Ninja Forms)accessed 2026-10-07
- PrimaryPatchstack's Ninja Forms vulnerability list, read in a browser on 7 October 2026: ten entries dated 4 September to about 2 October, used only to show that databases count differently.Patchstackaccessed 2026-10-07
- PrimaryCyber Essentials: Requirements for IT Infrastructure v3.3, April 2026, read in full: the Security Update Management requirement (14 days, three conditions), scope and cloud services.NCSCaccessed 2026-10-07
- PrimaryVulnerability management, 1. Put in place a policy to update by default, version 2.1, reviewed 1 May 2026: five, seven and 14 day timescales, licences, and the check-before-update advice for exploited services.NCSCaccessed 2026-10-07
- PrimaryGuidance to protect your website and custom email domain, published 29 May 2024: install CMS security updates, including themes and plugins.NCSCaccessed 2026-10-07
- PrimaryPersonal data breaches: a guide, read on 7 October 2026: the 72 hour rule, the likelihood of risk test, documenting decisions and processors' duty.ICOaccessed 2026-10-07
- PrimaryWordPress 5.5 release notes: auto-updates for plugins and themes can be turned on or off for each plugin.WordPress.orgaccessed 2026-10-07
- PrimaryUpgrading WordPress, the automatic background updates section: core updates by default, plugins and themes only in special cases.WordPress.orgaccessed 2026-10-07
- PrimaryMust-Use Plugins: they do not show in the default plugin list but appear in a separate Must-Use section and cannot be disabled from the admin screens.WordPress.orgaccessed 2026-10-07
- Reported byNinja Forms plugin flaw exploited to hack WordPress sites, 6 October 2026. The news pointer; read in a browser. It says both flaws require an authenticated session, which Wordfence, Patchstack and the CVE record contradict, so this briefing follows them.BleepingComputeraccessed 2026-10-07
- Reported byHackers exploit critical flaw in Ninja Forms WordPress plugin, 7 April 2026. The origin of the 3,600 attacks in 24 hours, the 600,000 downloads and the 90,000 customers figures that circulate with the October story.BleepingComputeraccessed 2026-10-07


