CVE-2026-15256: Unknown Ninja Forms

Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.

Affected products

  • Unknown Ninja Forms: before 3.14.10 (fixed in 3.14.10)

Published 2026-08-06. Last modified 2026-08-26.