PT-2026-30693 · WordPress · Ninja Forms - File Uploads

Sélim Lanouar

·

Published

2026-04-06

·

Updated

2026-04-07

·

CVE-2026-0740

CVSS v3.1

9.8

Critical

AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ninja Forms - File Uploads plugin for WordPress versions up to and including 3.3.26
Description The Ninja Forms - File Uploads plugin for WordPress has a flaw that allows unauthenticated attackers to upload arbitrary files. This is due to missing file type validation in the NF FU AJAX Controllers Uploads::handle upload function. Successful exploitation could lead to remote code execution. Approximately 50,000 WordPress sites are estimated to be affected. The vulnerability exists because the destination filename lacks file type validation, while the source filename is checked. This allows attackers to upload files with a .php extension and potentially perform path traversal to the webroot directory.
Recommendations Update to version 3.3.27

Fix

RCE

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

CVE-2026-0740

Affected Products

Ninja Forms - File Uploads