Impact
The Ninja Forms WordPress plugin fails to sanitize user‑supplied query‑string input that is used to pre‑populate a form field’s default value, resulting in that input being processed as a shortcode. This flaw allows an unauthenticated attacker to embed arbitrary shortcodes in the URL so that, when the form is rendered on a public page, the site’s PHP runtime executes those shortcodes.
Affected Systems
The affected component is the Ninja Forms plugin for WordPress, with all installed versions older than 3.14.10 being vulnerable. No other vendors or products are listed as affected.
Risk and Exploitability
No authentication is required; the attack vector is a crafted URL that sets a form field default via the query string. The CVSS score of 4.8 indicates moderate severity, while the EPSS score of <1% and absence from CISA’s KEV catalog suggest a low probability of widespread exploitation at present, though the vulnerability can be repeatedly used against any site running an outdated Ninja Forms installation.
OpenCVE Enrichment