CVE-2026-86612: Ninja Tables < 5.2.17 - Unauthenticated Arbitrary Shortcode Execution via Fluent Forms Data Source

Published Sep 23, 2026
·
Updated

The Ninja Tables WordPress plugin before 5.2.17 does not restrict shortcode expansion to administrator-authored table rows which, in a non-default configuration, allows unauthenticated users to have arbitrary shortcodes executed on a public page, and to permanently break that page, by submitting an ordinary form entry.

Affected Software

1 affected component
WPManageNinja Ninja Tables<5.2.17

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Ninja Tables to a version that resolves this vulnerability.

    Fixed in 5.2.17

Event History

Sep 23, 2026
CVE Published
via MITRE·10:11 AM
Data Sourced
via MITRE·10:11 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·11:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to this issue?

Sites using Ninja Tables versions before 5.2.17 are exposed only when configured to use Fluent Forms as a table data source and to display the affected table on a public page. This is a non-default configuration.

2

What does an attacker need to exploit it?

An attacker does not need authentication or user interaction. They need to be able to submit an ordinary Fluent Forms entry that is used in the vulnerable table data source.

3

What is the likely impact of successful exploitation?

An attacker can cause arbitrary shortcodes to be executed on the public page that renders the table. They can also permanently break that page through a submitted form entry.

4

How can I determine whether I may already be affected?

Review public pages that display Ninja Tables populated from Fluent Forms entries, and inspect the associated form submissions for shortcode content. A public table page that has become persistently broken after a form submission is an indicator of potential exploitation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203