AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-15256

MEDIUM · CVSS 4.8 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The Ninja Forms WordPress plugin prior to version 3.14.10 is vulnerable due to its failure to sanitize user-supplied query-string input, which can be exploited by unauthenticated attackers to execute arbitrary shortcodes on public pages. This could lead to unauthorized actions on the site, potentially compromising its integrity and security. WordPress administrators using this plugin should prioritize updating to the latest version to mitigate the risk of exploitation.

CVE
CVE-2026-15256
Severity
MEDIUM
CVSS
4.8
EPSS
0.19%
WordPress

Original NVD Description

The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.