PT-2026-30693 · WordPress · Ninja Forms - File Uploads
CVSS v2.0
10
Critical
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Ninja Forms - File Uploads versions prior to 3.3.27
Description
An unauthenticated arbitrary file upload issue exists due to missing file type and extension validation in the
NF FU AJAX Controllers Uploads::handle upload() function. This flaw allows attackers to upload arbitrary files, including PHP webshells, and use path traversal to move these files into the webroot, leading to remote code execution (RCE) and full site takeover. Approximately 50,000 sites are estimated to be affected, with thousands of exploitation attempts observed by security firms.Recommendations
Update Ninja Forms - File Uploads to version 3.3.27.
As a temporary workaround, disable or remove the File Uploads extension.
Scan the uploads directory and webroot for unexpected .php or suspicious files and remove them.
Apply WAF rules to block exploit patterns.
Rotate admin, database, and API credentials if a compromise is suspected.
Exploit
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ninja Forms - File Uploads