logo

Critical Vulnerability in Ninja Forms Plugin Exposes 50,000 WordPress Sites to RCE

ID: fc0e54fb-2028-540a-bbdc-d60740994ba7

STIX ID: report--fc0e54fb-2028-540a-bbdc-d60740994ba7

Feed Name: ThreatCluster

Threat Score
78/100

Date Published: 2026-04-07

Date Updated: 2026-04-08

...
...

**Executive Summary:** A critical unauthenticated file-upload vulnerability (CVE-2026-0740, CVSS 9.8) in the Ninja Forms File Uploads WordPress plugin allowed arbitrary file uploads and potential remote code execution across ~50,000 sites; active exploitation was observed and a complete patch was released on 2026-03-19, with immediate upgrades recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.