SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-80437

MEDIUM · CVSS 4.8 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-09-06 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Ninja Forms WordPress plugin versions prior to 3.15.2 are vulnerable due to inadequate validation of request-derived values, which allows unauthenticated users to execute any registered shortcode on the site. This could lead to unauthorized access or manipulation of site content, potentially compromising the integrity of the website. WordPress site administrators using affected versions should prioritize updating the plugin to mitigate this risk.

CVE
CVE-2026-80437
Severity
MEDIUM
CVSS
4.8
EPSS
0.23%
WordPress

Original NVD Description

The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.