logo

The Ninja’s Open Door: How a 9.8 CVSS Flaw Grants Hackers Full Control of 50,000 WordPress Sites

ID: 633e8cf7-f035-5603-a8ed-a87cf8fb0008

STIX ID: report--633e8cf7-f035-5603-a8ed-a87cf8fb0008

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-04-06

Date Updated: 2026-04-23

Author: Ddos

...
...

Critical RCE (CVE-2026-0740) in the Ninja Forms – File Upload WordPress plugin allows unauthenticated attackers to upload arbitrary PHP files and perform remote code execution due to missing validation on destination filenames and path traversal; affects versions up to 3.3.26 (~50k sites) and requires immediate update to 3.3.27+.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.