logo

Hackers exploit critical flaw in Ninja Forms WordPress plugin

ID: 7daa79c4-2f3d-5206-a186-4d5e27250ba3

STIX ID: report--7daa79c4-2f3d-5206-a186-4d5e27250ba3

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2026-04-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical CVE-2026-0740 in the Ninja Forms File Uploads premium add-on (CVSS 9.8) allows unauthenticated arbitrary file uploads and path traversal enabling remote code execution; Wordfence observed active exploitation (thousands of blocked attempts) and the vendor released a complete fix in version 3.3.27 — users should upgrade immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.