CVE-2026-15256: Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default
The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/ninja-formsto a version that resolves this vulnerability.Fixed in 3.14.10
Event History
Frequently Asked Questions
What is the severity of CVE-2026-15256?
CVE-2026-15256 has a medium severity rating of 4.8.
How do I fix CVE-2026-15256?
To fix CVE-2026-15256, update the Ninja Forms plugin to version 3.14.10 or later.
What impact does CVE-2026-15256 have on my website?
CVE-2026-15256 allows unauthenticated attackers to execute arbitrary shortcodes, potentially leading to unauthorized actions on your site.
Who is affected by CVE-2026-15256?
Users of the Ninja Forms WordPress plugin prior to version 3.14.10 are vulnerable to CVE-2026-15256.
Is CVE-2026-15256 easy to exploit?
Yes, CVE-2026-15256 can be exploited easily since it requires no authentication for the attacker.