THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-80437 (MEDIUM 4.8) — The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the sit

[NVD] CVE-2026-80437 (MEDIUM 4.8) — The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the sit

mednvdPublished 2026-09-06

CVE-2026-80437 CVSS: 4.8 MEDIUM Published: 2026-09-06T10:17:14.693

The Ninja Forms WordPress plugin from 3.14.10 before 3.15.2 does not prevent shortcodes in request-derived values from being executed when it substitutes them into content it later processes for shortcodes, allowing unauthenticated users to run any shortcode registered on the site.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-80437