logo

50,000 WordPress Sites Exposed to Critical Ninja Forms File Upload RCE Vulnerability

ID: b2226e88-f2af-5953-a93a-5b938779cb73

STIX ID: report--b2226e88-f2af-5953-a93a-5b938779cb73

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-04-07

Date Updated: 2026-04-21

Author: Abinaya

...
...

A critical unauthenticated arbitrary file upload vulnerability (CVE-2026-0740) in the Ninja Forms – File Upload WordPress plugin allows attackers to upload malicious PHP webshells via path traversal and improper filename validation, enabling remote code execution and full server compromise; approximately 50,000 sites were affected and a complete patch was released in version 3.3.27, so administrators must update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.