What is CVE-2026-15256?
CVE-2026-15256 is a vulnerability found in the Ninja Forms WordPress plugin versions prior to 3.14.10. It allows user-supplied query-string input, intended to pre-populate form field default values, to be processed as a shortcode, enabling unauthenticated attackers to execute arbitrary registered shortcodes on the affected site. To mitigate this issue, it is recommended to update the plugin to the latest version.
Azərbaycanca: CVE-2026-15256, Ninja Forms WordPress plagininin 3.14.10-dan əvvəlki versiyalarında aşkarlanmış boşluqdur. İstifadəçi tərəfindən göndərilən query-string girişi form sahələrinin standart dəyərini doldurmaq üçün işlənərkən yoxlanılmır və shortcode kimi icra olunur, bu da autentifikasiya olunmamış hücumçulara saytdakı ixtiyari shortcodeları işə salmağa imkan verir. Bu zəiflikdən qorunmaq üçün plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94
FAQ2
What WordPress plugin does CVE-2026-15256 affect?
CVE-2026-15256 affects the Ninja Forms plugin versions prior to 3.14.10.
How can I protect my site from this vulnerability?
To mitigate this issue, it is recommended to update the Ninja Forms plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.