PT-2026-30693 · WordPress · Ninja Forms - File Uploads

·

CVE-2026-0740

·

Published

2026-01-08

·

Updated

2026-08-21

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Ninja Forms - File Uploads versions prior to 3.3.27
Description An unauthenticated arbitrary file upload issue exists due to missing file type and extension validation in the NF FU AJAX Controllers Uploads::handle upload() function. This flaw allows attackers to upload arbitrary files, including PHP webshells, and use path traversal to move these files into the webroot, leading to remote code execution (RCE) and full site takeover. Approximately 50,000 sites are estimated to be affected, with thousands of exploitation attempts observed by security firms.
Recommendations Update Ninja Forms - File Uploads to version 3.3.27. As a temporary workaround, disable or remove the File Uploads extension. Scan the uploads directory and webroot for unexpected .php or suspicious files and remove them. Apply WAF rules to block exploit patterns. Rotate admin, database, and API credentials if a compromise is suspected.

Exploit

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-11299
CVE-2026-0740

Affected Products

Ninja Forms - File Uploads