The Ninja’s Open Door: How a 9.8 CVSS Flaw Grants Hackers Full Control of 50,000 WordPress Sites
ID: 633e8cf7-f035-5603-a8ed-a87cf8fb0008
STIX ID: report--633e8cf7-f035-5603-a8ed-a87cf8fb0008
Feed Name: securityonline.info
Threat Score
Critical RCE (CVE-2026-0740) in the Ninja Forms – File Upload WordPress plugin allows unauthenticated attackers to upload arbitrary PHP files and perform remote code execution due to missing validation on destination filenames and path traversal; affects versions up to 3.3.26 (~50k sites) and requires immediate update to 3.3.27+.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
