๐Ÿ” CVE Alert

CVE-2026-15256

MEDIUM 4.8

Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default

CVSS Score
4.8
EPSS Score
0.0%
EPSS Percentile
0th

The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.

Vendor unknown
Product ninja forms
Published Aug 6, 2026
Stay Ahead of the Next One

Get instant alerts for unknown ninja forms

Be the first to know when new medium vulnerabilities affecting unknown ninja forms are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Unknown / Ninja Forms
0 < 3.14.10

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/9c96f977-c105-4b45-a3cd-4751fb4aa5a1/

Credits

Meher Sudhakar Abbireddi WPScan