Impact
The vulnerability exists in Ninja Forms versions 3.14.10 through 3.15.1, where the plugin injects user‑supplied IP or Referer merge tag values directly into content that is subsequently processed for shortcodes. Because no sanitization or validation is performed, an unauthenticated user can place arbitrary WordPress shortcodes within those request‑derived values. When the form is rendered, the plugin processes the shortcodes, executing any shortcode that the site has registered. This can enable arbitrary code execution, data exfiltration, or modifications to site content if the attacker has access to privileged shortcodes.
Affected Systems
The affected product is the Ninja Forms WordPress plugin. All installations using version 3.14.10 up to and including 3.15.1 are vulnerable. Earlier or later versions are not affected. The plugin operates inside the WordPress content management system, so any WordPress site running those versions is at risk.
Risk and Exploitability
The CVSS base score of 4.8 indicates moderate severity. EPSS is not available and the vulnerability is not listed in the CISA KEV catalog, suggesting no known widespread exploitation to date. Nevertheless, the flaw requires no authentication and only a crafted HTTP request that includes a modified IP or Referer merge tag, so an attacker with internet access could potentially exploit the site. If a privileged shortcode is registered, the impact could range from data manipulation to full site compromise.
OpenCVE Enrichment