logo

Critical RCE Vulnerability in Ninja Forms Plugin Affects 50,000 WordPress Sites

ID: 9ba1f0f4-a496-5291-b4b5-c5d526343468

STIX ID: report--9ba1f0f4-a496-5291-b4b5-c5d526343468

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-07

...
...

A critical unauthenticated arbitrary file upload vulnerability (CVE-2026-0740) was disclosed in the Ninja Forms File Upload WordPress plugin, allowing attackers to upload malicious files and potentially achieve remote code execution; the issue (CVSS up to 9.8) affects roughly 50,000 sites and administrators are urged to update or disable the plugin immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.