CVE · Medium

CVE-2026-15256 — Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.14.10

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15256 Ninja Forms – The Contact Form Builder That Grows With You [ninja-forms] < 3.14.10 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') Medium 4.8 < 3.14.10 3.14.10 2026-08-06

CVE-2026-15256

The Ninja Forms WordPress plugin before version 3.14.10 allows unauthenticated attackers to execute arbitrary shortcodes on a site by embedding a form with a malicious query-string input that is processed as a shortcode, potentially leading to unauthorized execution of registered shortcodes.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.