50,000 WordPress Sites Exposed to Critical Ninja Forms File Upload RCE Vulnerability
ID: b2226e88-f2af-5953-a93a-5b938779cb73
STIX ID: report--b2226e88-f2af-5953-a93a-5b938779cb73
Feed Name: cybersecurityNews.com
Threat Score
A critical unauthenticated arbitrary file upload vulnerability (CVE-2026-0740) in the Ninja Forms – File Upload WordPress plugin allows attackers to upload malicious PHP webshells via path traversal and improper filename validation, enabling remote code execution and full server compromise; approximately 50,000 sites were affected and a complete patch was released in version 3.3.27, so administrators must update immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
