CVE-2026-15256
4.8
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:N
Summary
The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | Ninja Forms | 0 < 3.14.10 | affected |
Weaknesses
- CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.