CVE-2026-80437: Ninja Forms 3.14.10 - 3.15.1 - Unauthenticated Arbitrary Shortcode Execution via IP and Referer Merge Tags
Published Sep 6, 2026
·Updated
The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.
Affected Software
1 affected component
WordPress Ninja Forms>=3.14.10<3.15.2
Event History
Sep 6, 2026
CVE Published
via MITRE·09:36 AM
Data Sourced
via MITRE·09:36 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which installations are affected?
WordPress sites using Ninja Forms versions 3.14.10 through 3.15.1 are affected. Upgrade the plugin to version 3.15.2.
2
Does exploitation require a WordPress account or user interaction?
No. The issue can be exploited by an unauthenticated attacker and does not require user interaction.
3
What determines the potential impact on a particular site?
The attacker can execute any shortcode registered on the site. The practical impact therefore depends on which shortcodes are available and what those shortcodes do when run.