50,000 WordPress Sites Running Ninja Forms Vulnerable to Critical File Upload RCE
ID: 600c1861-0f00-5881-99bc-e433b55ba671
STIX ID: report--600c1861-0f00-5881-99bc-e433b55ba671
Feed Name: GBHackers
Threat Score
A critical unauthenticated arbitrary file upload vulnerability (CVE-2026-0740) in the Ninja Forms File Upload WordPress plugin allows attackers to bypass filename checks and use path traversal to place and execute malicious PHP files in web-accessible locations, enabling remote code execution. The issue (CVSS 9.8) affects an estimated 50,000 active installs; Wordfence deployed temporary firewall rules and the vendor released a full patch in version 3.3.27 (March 19, 2026).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
