CVE-2026-80437: Unknown Ninja Forms

Medium severity, CVSS 4.8. EPSS: 0.2% chance of exploitation in the next 30 days.

The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.

Affected products

  • Unknown Ninja Forms: from 3.14.10, before 3.15.2 (fixed in 3.15.2)

Published 2026-09-06. Last modified 2026-09-08.