Register for the AI for Security Summit: Join Figma, Perplexity & Wiz

CVE-2026-80437
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-80437 is an unauthenticated arbitrary shortcode execution vulnerability in the Ninja Forms WordPress plugin, affecting versions 3.14.10 through 3.15.1. The flaw allows unauthenticated users to execute any shortcode registered on the affected WordPress site by injecting shortcodes into request-derived values (such as IP address and Referer merge tags) that the plugin later processes. It was publicly disclosed on September 4, 2026, with a patch released in version 3.15.2. The CVE carries a CVSS v3.1 base score of 4.8 (Medium) (WPScan, GitHub Advisory).

Technical details

The root cause is classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — Injection). The plugin substitutes request-derived values, specifically IP address and HTTP Referer merge tags, into content that is subsequently processed for WordPress shortcodes, without sanitizing or neutralizing shortcode syntax in those values. A prior release had neutralized only one of the affected value sources, leaving others exploitable. Exploitation requires the site to be configured to display one of the affected merge tag values (e.g., in a form confirmation message), and attack complexity is rated High due to this configuration prerequisite (WPScan, GitHub Advisory).

Impact

Successful exploitation allows an unauthenticated remote attacker to execute any WordPress shortcode registered on the target site. Depending on which shortcodes are installed and available, this could result in unauthorized reading of sensitive data, modification of site content, or execution of administrative actions. The availability impact is rated None, while both confidentiality and integrity are rated Low, reflecting the bounded but real risk of shortcode-level access (GitHub Advisory, WPScan).

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. WPScan noted that a PoC was scheduled for release on September 16, 2026, to allow time for users to update. The EPSS score is approximately 0.233% (14th percentile), indicating a low near-term exploitation probability. The CVE status is listed as "Deferred" and is not currently listed in the CISA Known Exploited Vulnerabilities catalog (WPScan, GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running Ninja Forms versions 3.14.10–3.15.1 using tools like WPScan or by inspecting plugin version metadata in publicly accessible files (e.g., readme.txt).
  2. Identify configuration prerequisite: Confirm that the target site is configured to display IP address or HTTP Referer merge tags in a Ninja Forms output context (e.g., form confirmation messages or email notifications).
  3. Craft malicious request: Submit a form request to the target site with a shortcode payload embedded in the HTTP X-Forwarded-For or Referer header — for example, setting the Referer header to [some_registered_shortcode].
  4. Trigger shortcode execution: When the plugin processes the form submission and substitutes the merge tag value into content that is then evaluated for shortcodes, the injected shortcode is executed server-side.
  5. Achieve objective: Depending on available shortcodes, the attacker may read sensitive site data, trigger content changes, or invoke plugin-specific functionality (WPScan).

Indicators of compromise

  • Network: Unusual or malformed values in HTTP Referer or X-Forwarded-For headers on form submission requests, particularly containing WordPress shortcode syntax (e.g., [shortcode_name]).
  • Logs: WordPress or web server access logs showing form POST requests with shortcode-like strings in header fields; unexpected shortcode output appearing in form confirmation emails or on-page responses.
  • Application Behavior: Unexpected execution of registered shortcodes in form confirmation messages or email notifications not attributable to legitimate site content; unusual plugin or theme behavior triggered without authenticated user action.

Mitigation and workarounds

The vendor has released a patch in Ninja Forms version 3.15.2, which neutralizes shortcode injection across all affected request-derived value sources. Site administrators should update the Ninja Forms plugin to version 3.15.2 or later immediately. As an interim measure, administrators can review and disable any form configurations that display IP address or HTTP Referer merge tags in processed content. Regularly auditing installed plugins and shortcodes for trusted sources is also recommended (WPScan, GitHub Advisory).

Community reactions

The vulnerability was discovered and reported by researcher Jakub Herman, who submitted it to WPScan. WPScan applied a coordinated disclosure timeline, withholding the proof-of-concept until September 16, 2026, to allow site operators time to update. No significant broader media coverage or notable social media commentary has been identified beyond standard vulnerability database aggregation (WPScan).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-93031HIGH8.8
  • use-your-drive
NoYesSep 18, 2026
CVE-2026-87915HIGH7.2
  • popup-maker
NoYesSep 18, 2026
CVE-2026-18405HIGH7.2
  • jeg-elementor-kit
NoYesSep 18, 2026
CVE-2026-15797MEDIUM6.4
  • popup-maker
NoYesSep 18, 2026
CVE-2026-90884MEDIUM5.4
  • wp-recipe-maker
NoYesSep 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management