Description
The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.
Published: 2026-08-06
Score: 4.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Ninja Forms WordPress plugin fails to sanitize user-supplied query-string input that is used to pre‑populate a form field’s default value. As a result, an unauthenticated attacker can embed arbitrary shortcodes in the URL so that when a form configured in this way is loaded on a public page, those shortcodes are processed and executed by the site’s PHP runtime. This flaw allows the execution of any shortcode registered on the site, potentially leading to arbitrary code execution, data exfiltration, or content tampering. The issue carries a CVSS score of 4.8, indicating moderate severity.

Affected Systems

The impacted component is the Ninja Forms plugin for WordPress, affecting all installed versions prior to 3.14.10. No other vendors or products are listed as affected.

Risk and Exploitability

No authentication is required and the attack vector is a simple crafted URL that includes a query-string parameter to set a form field default. The exploit is trivial for an attacker who can reach a public page that renders the vulnerable form, and because any shortcode registered on the site will run, the actual impact depends on the attacker’s choice of shortcode. The EPSS score is not available and the vulnerability is not listed in CISA’s KEV catalog, but the lack of input validation combined with the ability to execute arbitrary shortcodes means that once discovered, the flaw could be used repeatedly against any site using an outdated Ninja Forms installation.

Generated by OpenCVE AI on August 6, 2026 at 23:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Ninja Forms to version 3.14.10 or later to obtain the vendor’s patch that removes the query‑string processing flaw.
  • If an immediate upgrade is not possible, disable or filter the form field default values that can be set via query string to prevent arbitrary content from being interpreted as a shortcode. This reduces the risk by enforcing input validation on the field’s default value.
  • Check the list of shortcodes active on the site and remove or disable any that are unnecessary; limiting the available shortcode set decreases the potential impact of any remaining exploitation attempts.

Generated by OpenCVE AI on August 6, 2026 at 23:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 07 Aug 2026 00:00:00 +0000

Type Values Removed Values Added
First Time appeared Ninjaforms
Ninjaforms ninja Forms
Wordpress
Wordpress wordpress
Vendors & Products Ninjaforms
Ninjaforms ninja Forms
Wordpress
Wordpress wordpress

Thu, 06 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.
Title Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default
References
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Ninjaforms Ninja Forms
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-06T17:14:40.246Z

Reserved: 2026-07-09T13:02:53.705Z

Link: CVE-2026-15256

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T23:45:03Z

Weaknesses

No weakness.