CVE-2026-15256

Ninja Forms < 3.14.10 - Unauthenticated Arbitrary Shortcode Execution via Query-String Populated Field Default

The Ninja Forms WordPress plugin before 3.14.10 does not prevent user-supplied query-string input, used to pre-populate a form field's default value, from being processed as a shortcode, allowing unauthenticated attackers to execute arbitrary shortcodes registered on the site when a form so configured is embedded on a public page.


We have discovered 112,729 live websites that are affected by CVE-2026-15256.

Run a Free Instant Scan




Affected Software

Product  Ninja Forms
Category Form Builders
Vulnerable Domains112,729 live websites (90% of Ninja Forms install base)
Vulnerable Versions
  • from 0 through 3.14.10
Vulnerable Versions Count240 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')



Details

  • Published - Aug 6, 2026
  • Updated - Aug 7, 2026

Credits

  • Meher Sudhakar Abbireddi (finder)
  • WPScan (coordinator)

Website Distribution by Country

Number of websites using CVE-2026-15256
United States48,729 websites



Germany10,489 websites
GB7,920 websites
France5,995 websites
Netherlands4,802 websites
Canada3,396 websites
Australia3,188 websites
Italy2,682 websites
Spain2,305 websites
Switzerland1,953 websites

Website Distribution by TLD

Number of websites using CVE-2026-15256
.com54,057 websites
.org7,395 websites
.de6,755 websites
.co.uk5,403 websites
.nl4,415 websites
.com.au2,917 websites
.fr2,836 websites
.net2,456 websites
.ca1,976 websites
.it1,787 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15256

Top websites that are affected by CVE-2026-15256. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****.com United States***
****.org United States*,***
****.ca United States*,***
**********.com United States*,***
***********.com United States*,***
****************.com United States*,***
**********.de Germany*,***
************.com United States**,***
**********.ro Romania**,***
**************.com United States**,***
See full domain list

FAQ

CVE-2026-15256 is Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in Ninja Forms
A total of 112,729 websites have been identified as vulnerable to CVE-2026-15256, based on global website indexing conducted by WebTechSurvey.
The Ninja Forms is affected by the CVE-2026-15256 vulnerability.
Ninja Forms versions up to 3.14.10 are vulnerable to CVE-2026-15256.
CVE-2026-15256 is resolved in version 3.14.10 of Ninja Forms.