CyberRota Analysis
AI-GeneratedThe Ninja Forms WordPress plugin versions prior to 3.15.2 are vulnerable due to inadequate validation of request-derived values, which allows unauthenticated users to execute any registered shortcode on the site. This could lead to unauthorized access or manipulation of site content, potentially compromising the integrity of the website. WordPress site administrators using affected versions should prioritize updating the plugin to mitigate this risk.
Original NVD Description
The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.