PT-2026-104083 · WordPress · Ninja Forms - File Uploads
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ninja Forms - File Uploads versions prior to 3.3.35
Description
An issue exists in the external (Amazon S3) upload flow where the plugin trusts a file path supplied by the user during form submission and stores it as the
file path variable. This variable is used without validation, allowing unauthenticated attackers to perform arbitrary file operations. Specifically, this can lead to arbitrary file read when a form Email action is configured to attach the uploaded file, arbitrary file write which can result in remote code execution when the external store is configured, and arbitrary file deletion through scheduled cleanup. Exploitation requires the site to have the External File Upload (Amazon S3) action enabled.Recommendations
Update Ninja Forms - File Uploads to version 3.3.35 or later.
As a temporary mitigation, disable the External File Upload (Amazon S3) action.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ninja Forms - File Uploads