PT-2026-63839 · Ninjaforms+1 · Ninja Forms - File Uploads Extension+1
CVE-2026-57784
·
Published
2026-04-08
·
Updated
2026-07-23
CVSS v3.1
9.6
Critical
| Vector | AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Ninja Forms File Uploads Extension versions prior to 3.3.27
Description
An unauthenticated Cross-Site Request Forgery (CSRF) issue exists in the Ninja Forms File Uploads Extension plugin for WordPress. This occurs due to missing or incorrect nonce validation—a security mechanism used to ensure that a request was intentionally sent by the user—within a function. This allows an attacker to perform unauthorized actions by tricking a site administrator into clicking a malicious link.
Recommendations
Update Ninja Forms File Uploads Extension to a version newer than 3.3.26.
Fix
CSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ninja Forms - File Uploads Extension
Ninja-Forms-Uploads