CVE-2026-86612: Ninja Tables < 5.2.17 - Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Data Source
The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table rows which, in a non-default configuration, allows unauthenticated users to have arbitrary shortcodes executed on a public page, and to permanently break that page, by submitting an ordinary form entry.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Ninja Tablesto a version that resolves this vulnerability.Fixed in 5.2.17
Event History
Frequently Asked Questions
Which sites are exposed to this issue?
Sites using Ninja Tables versions before 5.2.17 are exposed only when configured to use Fluent Forms as a table data source and to display the affected table on a public page. This is a non-default configuration.
What does an attacker need to exploit it?
An attacker does not need authentication or user interaction. They need to be able to submit an ordinary Fluent Forms entry that is used in the vulnerable table data source.
What is the likely impact of successful exploitation?
An attacker can cause arbitrary shortcodes to be executed on the public page that renders the table. They can also permanently break that page through a submitted form entry.
How can I determine whether I may already be affected?
Review public pages that display Ninja Tables populated from Fluent Forms entries, and inspect the associated form submissions for shortcode content. A public table page that has become persistently broken after a form submission is an indicator of potential exploitation.