PT-2026-63839 · Ninjaforms+1 · Ninja Forms - File Uploads Extension+1

CVE-2026-57784

·

Published

2026-04-08

·

Updated

2026-07-23

CVSS v3.1

9.6

Critical

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Ninja Forms File Uploads Extension versions prior to 3.3.27
Description An unauthenticated Cross-Site Request Forgery (CSRF) issue exists in the Ninja Forms File Uploads Extension plugin for WordPress. This occurs due to missing or incorrect nonce validation—a security mechanism used to ensure that a request was intentionally sent by the user—within a function. This allows an attacker to perform unauthorized actions by tricking a site administrator into clicking a malicious link.
Recommendations Update Ninja Forms File Uploads Extension to a version newer than 3.3.26.

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57784

Affected Products

Ninja Forms - File Uploads Extension
Ninja-Forms-Uploads