Critical RCE Vulnerability in Ninja Forms Plugin Affects 50,000 WordPress Sites
ID: 9ba1f0f4-a496-5291-b4b5-c5d526343468
STIX ID: report--9ba1f0f4-a496-5291-b4b5-c5d526343468
Feed Name: ThreatCluster
Threat Score
A critical unauthenticated arbitrary file upload vulnerability (CVE-2026-0740) was disclosed in the Ninja Forms File Upload WordPress plugin, allowing attackers to upload malicious files and potentially achieve remote code execution; the issue (CVSS up to 9.8) affects roughly 50,000 sites and administrators are urged to update or disable the plugin immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
