
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-80437 is an unauthenticated arbitrary shortcode execution vulnerability in the Ninja Forms WordPress plugin, affecting versions 3.14.10 through 3.15.1. The flaw allows unauthenticated users to execute any shortcode registered on the affected WordPress site by injecting shortcodes into request-derived values (such as IP address and Referer merge tags) that the plugin later processes. It was publicly disclosed on September 4, 2026, with a patch released in version 3.15.2. The CVE carries a CVSS v3.1 base score of 4.8 (Medium) (WPScan, GitHub Advisory).
The root cause is classified as CWE-74 (Improper Neutralization of Special Elements in Output Used by a Downstream Component — Injection). The plugin substitutes request-derived values, specifically IP address and HTTP Referer merge tags, into content that is subsequently processed for WordPress shortcodes, without sanitizing or neutralizing shortcode syntax in those values. A prior release had neutralized only one of the affected value sources, leaving others exploitable. Exploitation requires the site to be configured to display one of the affected merge tag values (e.g., in a form confirmation message), and attack complexity is rated High due to this configuration prerequisite (WPScan, GitHub Advisory).
Successful exploitation allows an unauthenticated remote attacker to execute any WordPress shortcode registered on the target site. Depending on which shortcodes are installed and available, this could result in unauthorized reading of sensitive data, modification of site content, or execution of administrative actions. The availability impact is rated None, while both confidentiality and integrity are rated Low, reflecting the bounded but real risk of shortcode-level access (GitHub Advisory, WPScan).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of in-the-wild exploitation. WPScan noted that a PoC was scheduled for release on September 16, 2026, to allow time for users to update. The EPSS score is approximately 0.233% (14th percentile), indicating a low near-term exploitation probability. The CVE status is listed as "Deferred" and is not currently listed in the CISA Known Exploited Vulnerabilities catalog (WPScan, GitHub Advisory).
readme.txt).X-Forwarded-For or Referer header — for example, setting the Referer header to [some_registered_shortcode].Referer or X-Forwarded-For headers on form submission requests, particularly containing WordPress shortcode syntax (e.g., [shortcode_name]).The vendor has released a patch in Ninja Forms version 3.15.2, which neutralizes shortcode injection across all affected request-derived value sources. Site administrators should update the Ninja Forms plugin to version 3.15.2 or later immediately. As an interim measure, administrators can review and disable any form configurations that display IP address or HTTP Referer merge tags in processed content. Regularly auditing installed plugins and shortcodes for trusted sources is also recommended (WPScan, GitHub Advisory).
The vulnerability was discovered and reported by researcher Jakub Herman, who submitted it to WPScan. WPScan applied a coordinated disclosure timeline, withholding the proof-of-concept until September 16, 2026, to allow site operators time to update. No significant broader media coverage or notable social media commentary has been identified beyond standard vulnerability database aggregation (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."