LeakyCreds
NewInstant webhook alerts now available — notified within seconds of any credential detection.Learn more →

CVE-2026-0740 - Vulnerability Analysis

CriticalCVSS: 9.8

Last Updated: April 7, 2026

Ninja Forms - File Uploads - Unrestricted File Upload

Published: April 7, 2026Updated: April 7, 2026KEVPoC AvailableRemote Exploitable

Overview

Ninja Forms - File Uploads plugin for WordPress <= 3.3.26 contains an unrestricted file upload vulnerability caused by missing file type validation in NF_FU_AJAX_Controllers_Uploads::handle_upload, letting unauthenticated attackers upload arbitrary files, exploit requires no authentication.

Severity & Score

Severity: Critical
CVSS Score: 9.8
EPSS Score: 8.3%(Probability of exploitation in next 30 days)

Impact

Unauthenticated attackers can upload arbitrary files, potentially leading to remote code execution and full server compromise.

Mitigation

Update to version 3.3.27 or later.

Social Media Activity(1 post)

BeyondMachines :verified:
BeyondMachines :verified:
@beyondmachines1
Apr 8, 2026

Critical File Upload Vulnerability Reported in Ninja Forms Plugin for WordPress A critical unauthenticated arbitrary file upload vulnerability in the Ninja Forms – File Upload plugin (CVE-2026-0740) allows attackers to achieve remote code execution. **If you are using the Ninja Forms File Upload plugin, this is urgent! Immediately update to version 3.3.27. You can't hide WordPress from the internet, it's made to be visible online. Since this flaw is being actively scanned for, any delay in patching leaves your site exposed to automated attacks. After the update, review server logs for suspicious requests targeting the handle_upload action.** #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/critical-file-upload-vulnerability-in-ninja-forms-plugin-exposes-50000-wordpress-sites-j-m-6-0-i/gD2P6Ple2L

View original post

Details

CVE ID
CVE-2026-0740
Severity
Critical
CVSS Score
9.8
Type
unrestricted_file_upload
Status
unconfirmed
EPSS
8.3%
Social Posts
1

CWE

  • CWE-434

CVSS Metrics

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score

8.3%Probability of exploitation in the next 30 days