CVE-2026-0740 - Vulnerability Analysis
CriticalCVSS: 9.8Last Updated: April 7, 2026
Ninja Forms - File Uploads - Unrestricted File Upload
Overview
Ninja Forms - File Uploads plugin for WordPress <= 3.3.26 contains an unrestricted file upload vulnerability caused by missing file type validation in NF_FU_AJAX_Controllers_Uploads::handle_upload, letting unauthenticated attackers upload arbitrary files, exploit requires no authentication.
Severity & Score
Impact
Unauthenticated attackers can upload arbitrary files, potentially leading to remote code execution and full server compromise.
Mitigation
Update to version 3.3.27 or later.
References
- https://www.wordfence.com/threat-intel/vulnerabilities/wordpress-plugins/ninja-forms-uploads/ninja-forms-file-upload-3326-unauthenticated-arbitrary-file-upload
- https://ninjaforms.com/extensions/file-uploads/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/0b606ded-ab50-486a-9337-97ee9f452f12?source=cve
Social Media Activity(1 post)
Critical File Upload Vulnerability Reported in Ninja Forms Plugin for WordPress A critical unauthenticated arbitrary file upload vulnerability in the Ninja Forms – File Upload plugin (CVE-2026-0740) allows attackers to achieve remote code execution. **If you are using the Ninja Forms File Upload plugin, this is urgent! Immediately update to version 3.3.27. You can't hide WordPress from the internet, it's made to be visible online. Since this flaw is being actively scanned for, any delay in patching leaves your site exposed to automated attacks. After the update, review server logs for suspicious requests targeting the handle_upload action.** #cybersecurity #infosec #advisory #vulnerability https://beyondmachines.net/event_details/critical-file-upload-vulnerability-in-ninja-forms-plugin-exposes-50000-wordpress-sites-j-m-6-0-i/gD2P6Ple2L
View original postGitHub Repositories(1 repo)
Related Resources
Details
- CVE ID
- CVE-2026-0740
- Severity
- Critical
- CVSS Score
- 9.8
- Type
- unrestricted_file_upload
- Status
- unconfirmed
- EPSS
- 8.3%
- Social Posts
- 1
CWE
- CWE-434
CVSS Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H