Medium · 4.2 WordPress CVE-2026-80437
Ninja Forms WordPress Plugin: Unauthenticated Shortcode Injection Vulnerability (CVE-2026-80437)
Versions of the Ninja Forms WordPress plugin from 3.14.10 up to but not including 3.15.2 fail to prevent shortcodes embedded in request-derived values from being executed, allowing unauthenticated users to trigger any shortcode registered on the site. No fixed version has been confirmed yet.
AI summary
A vulnerability has been published affecting the Ninja Forms WordPress plugin, a widely used contact form builder with over 500,000 active installations. The issue, tracked as CVE-2026-80437, allows unauthenticated attackers to execute any shortcode registered on an affected site by submitting specially crafted request values. This briefing summarizes what is currently known based on the validated advisory data.
What Happened
The Ninja Forms WordPress plugin, in versions from 3.14.10 up to (but not including) 3.15.2, does not prevent shortcodes contained in request-derived values from being executed when those values are later substituted into content that the plugin processes for shortcodes. As a result, an unauthenticated user can cause the site to run any shortcode that is registered on it, simply by crafting appropriate request input.
Technical Cause
The root cause is insufficient sanitization or filtering of user-supplied, request-derived values before they are inserted into content that is subsequently parsed for shortcodes. Because WordPress shortcode processing will execute any recognized shortcode found in content, injecting a shortcode string through request data causes it to run with the privileges and effects normally associated with that shortcode, without requiring authentication.
Why It Matters
Because the attacker does not need to be authenticated and no user interaction is required, this vulnerability can be exploited remotely by any visitor to a site running the affected plugin. The practical impact depends on which other shortcodes are registered on the site — some shortcodes may expose limited information or trigger limited actions (reflected in the CVSS impact scores of low confidentiality and integrity impact, no availability impact), while the broader risk depends on the site's specific plugin and theme ecosystem.
Who Is Affected
Any WordPress site running the Ninja Forms plugin in a version from 3.14.10 up to (but not including) 3.15.2 is affected. Ninja Forms is reported to have more than 500,000 active installations, making this a widely deployed plugin.
Affected Versions
Affected: Ninja Forms versions from 3.14.10 up to, but not including, 3.15.2. The advisory data references version 3.15.2 as the boundary marking the end of the affected range, but it does not explicitly confirm that 3.15.2 or any later version contains a fix.
Fixes and Mitigation
The fact package indicates that no fix is currently confirmed to be available for this vulnerability. We cannot state with certainty that upgrading to version 3.15.2 resolves the issue, since this was not explicitly confirmed in the source data. Site operators should monitor the official Ninja Forms plugin changelog and the WordPress plugin repository for an update addressing this issue.
Recommended Action
Site administrators running Ninja Forms should check their installed version and consult official vendor channels for a confirmed security update. Until a fix is confirmed, consider auditing which shortcodes are registered on the site to understand potential exposure, and monitor for unusual form submission activity. Apply any available plugin update promptly once the vendor confirms a patched release.
PatchBriefing score
4.2 / 10 · Medium
Official CVSS: 4.8
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Why this score
This vulnerability has a patchwire_score of 4.2 and a CVSS base score of 4.8 (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N), reflecting a network-exploitable issue that requires no privileges or user interaction but has high attack complexity, and results in low confidentiality and integrity impact with no availability impact. The score is further influenced by the facts that the vulnerability can be exploited by unauthenticated remote attackers (contributing 0.6), requires no user interaction (contributing 0.2), currently has no confirmed fix available (contributing 0.4), and affects a plugin with an estimated install base of 500,000 sites (contributing 0.36). There is no evidence of known exploitation in the wild or public exploit code.
Affected versions
- Ninja Forms < 3.15.2
- vulnerable
Reported fixes
The fact package indicates that no fix is currently confirmed to be available for this vulnerability. We cannot state with certainty that upgrading to version 3.15.2 resolves the issue, since this was not explicitly confirmed in the source data. Site operators should monitor the official Ninja Forms plugin changelog and the WordPress plugin repository for an update addressing this issue.
How this was built
1 source records were collected, matched and used to prepare the report above.
-
WPVulnerability database
Revision history
- Published
- Generated
Related
Relevant changes for the stacks you follow.
Choose your stacks, topics and optional WordPress plugins. At 07:00 CEST, matching advisories and releases from the reporting period are grouped into one email.
✓ Choose stacks and topics✓ Change preferences anytime✓ One grouped email