PT-2026-104083 · WordPress · Ninja Forms - File Uploads

·

CVE-2026-92820

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ninja Forms - File Uploads versions prior to 3.3.35
Description An issue exists in the external (Amazon S3) upload flow where the plugin trusts a file path supplied by the user during form submission and stores it as the file path variable. This variable is used without validation, allowing unauthenticated attackers to perform arbitrary file operations. Specifically, this can lead to arbitrary file read when a form Email action is configured to attach the uploaded file, arbitrary file write which can result in remote code execution when the external store is configured, and arbitrary file deletion through scheduled cleanup. Exploitation requires the site to have the External File Upload (Amazon S3) action enabled.
Recommendations Update Ninja Forms - File Uploads to version 3.3.35 or later. As a temporary mitigation, disable the External File Upload (Amazon S3) action.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92820

Affected Products

Ninja Forms - File Uploads