PT-2026-30693 · WordPress · Ninja Forms - File Uploads
Sélim Lanouar
·
Published
2026-04-06
·
Updated
2026-04-07
·
CVE-2026-0740
CVSS v3.1
9.8
Critical
| AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ninja Forms - File Uploads plugin for WordPress versions up to and including 3.3.26
Description
The Ninja Forms - File Uploads plugin for WordPress has a flaw that allows unauthenticated attackers to upload arbitrary files. This is due to missing file type validation in the
NF FU AJAX Controllers Uploads::handle upload function. Successful exploitation could lead to remote code execution. Approximately 50,000 WordPress sites are estimated to be affected. The vulnerability exists because the destination filename lacks file type validation, while the source filename is checked. This allows attackers to upload files with a .php extension and potentially perform path traversal to the webroot directory.Recommendations
Update to version 3.3.27
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ninja Forms - File Uploads