Skip to content
PatchBriefing

Search PatchBriefing

Type at least two characters. Results update as you type.

Search CVEs, products, packages and article titles.

Nothing found. Identifiers such as CVE and GHSA can be searched in both languages.

Subscribe

Medium · 4.2 WordPress CVE-2026-80437

Ninja Forms WordPress Plugin: Unauthenticated Shortcode Injection Vulnerability (CVE-2026-80437)

Versions of the Ninja Forms WordPress plugin from 3.14.10 up to but not including 3.15.2 fail to prevent shortcodes embedded in request-derived values from being executed, allowing unauthenticated users to trigger any shortcode registered on the site. No fixed version has been confirmed yet.

Synthesized by AI from 1 source · updated 1 hour ago
Sources · merged by AI 1 total

AI summary

A vulnerability has been published affecting the Ninja Forms WordPress plugin, a widely used contact form builder with over 500,000 active installations. The issue, tracked as CVE-2026-80437, allows unauthenticated attackers to execute any shortcode registered on an affected site by submitting specially crafted request values. This briefing summarizes what is currently known based on the validated advisory data.

What Happened

The Ninja Forms WordPress plugin, in versions from 3.14.10 up to (but not including) 3.15.2, does not prevent shortcodes contained in request-derived values from being executed when those values are later substituted into content that the plugin processes for shortcodes. As a result, an unauthenticated user can cause the site to run any shortcode that is registered on it, simply by crafting appropriate request input.

Technical Cause

The root cause is insufficient sanitization or filtering of user-supplied, request-derived values before they are inserted into content that is subsequently parsed for shortcodes. Because WordPress shortcode processing will execute any recognized shortcode found in content, injecting a shortcode string through request data causes it to run with the privileges and effects normally associated with that shortcode, without requiring authentication.

Why It Matters

Because the attacker does not need to be authenticated and no user interaction is required, this vulnerability can be exploited remotely by any visitor to a site running the affected plugin. The practical impact depends on which other shortcodes are registered on the site — some shortcodes may expose limited information or trigger limited actions (reflected in the CVSS impact scores of low confidentiality and integrity impact, no availability impact), while the broader risk depends on the site's specific plugin and theme ecosystem.

Who Is Affected

Any WordPress site running the Ninja Forms plugin in a version from 3.14.10 up to (but not including) 3.15.2 is affected. Ninja Forms is reported to have more than 500,000 active installations, making this a widely deployed plugin.

Affected Versions

Affected: Ninja Forms versions from 3.14.10 up to, but not including, 3.15.2. The advisory data references version 3.15.2 as the boundary marking the end of the affected range, but it does not explicitly confirm that 3.15.2 or any later version contains a fix.

Fixes and Mitigation

The fact package indicates that no fix is currently confirmed to be available for this vulnerability. We cannot state with certainty that upgrading to version 3.15.2 resolves the issue, since this was not explicitly confirmed in the source data. Site operators should monitor the official Ninja Forms plugin changelog and the WordPress plugin repository for an update addressing this issue.

Recommended Action

Site administrators running Ninja Forms should check their installed version and consult official vendor channels for a confirmed security update. Until a fix is confirmed, consider auditing which shortcodes are registered on the site to understand potential exposure, and monitor for unusual form submission activity. Apply any available plugin update promptly once the vendor confirms a patched release.

PatchBriefing score

4.2 / 10 · Medium

Official CVSS: 4.8

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N

Why this score

This vulnerability has a patchwire_score of 4.2 and a CVSS base score of 4.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N), reflecting a network-exploitable issue that requires no privileges or user interaction but has high attack complexity, and results in low confidentiality and integrity impact with no availability impact. The score is further influenced by the facts that the vulnerability can be exploited by unauthenticated remote attackers (contributing 0.6), requires no user interaction (contributing 0.2), currently has no confirmed fix available (contributing 0.4), and affects a plugin with an estimated install base of 500,000 sites (contributing 0.36). There is no evidence of known exploitation in the wild or public exploit code.

Affected versions

Ninja Forms < 3.15.2
vulnerable

Reported fixes

The fact package indicates that no fix is currently confirmed to be available for this vulnerability. We cannot state with certainty that upgrading to version 3.15.2 resolves the issue, since this was not explicitly confirmed in the source data. Site operators should monitor the official Ninja Forms plugin changelog and the WordPress plugin repository for an update addressing this issue.

How this was built

1 source records were collected, matched and used to prepare the report above.

  • WPVulnerability database
Unified report
Ninja Forms WordPress Plugin: Unauthenticated Shortcode Injection Vulnerability (CVE-2026-80437)
1 article · 1 sources cited
Revision history
  1. Published
  2. Generated
The Morning Brief

Relevant changes for the stacks you follow.

Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.

✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email