PT-2022-13503 · WordPress · Ninja Forms - File Uploads Extension

Muhammad Zeeshan

·

Published

2022-03-23

·

Updated

2024-01-11

·

CVE-2022-0888

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ninja Forms - File Uploads Extension WordPress plugin versions up to and including 3.3.0
Description The issue is related to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file, which can be bypassed. This allows unauthenticated attackers to upload malicious files, potentially leading to remote code execution.
Recommendations For versions up to and including 3.3.0, update to a version later than 3.3.0 to resolve the issue. As a temporary workaround, consider restricting access to the ~/includes/ajax/controllers/uploads.php file to minimize the risk of exploitation. Avoid using the file upload functionality in the affected plugin until the issue is resolved.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-0888

Affected Products

Ninja Forms - File Uploads Extension