cleantalk
Vulnerabilities and Security Researches

Ninja Forms Contact Form – The Drag and Drop Form Builder for WordPress, CVE-2026-80437

CVE, Research URL

CVE-2026-80437

Published on
Sep 06, 2026
Research Description
The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.
Affected versions
max 3.15.2.
Status
vulnerable