logo

Critical Vulnerability in Ninja Forms Exposes WordPress Sites

ID: 58054cef-e63b-56b3-8aee-2f3954c6ac7c

STIX ID: report--58054cef-e63b-56b3-8aee-2f3954c6ac7c

Feed Name: Infosecurity Magazine (News)

Threat Score
80/100

Date Published: 2026-04-08

Date Updated: 2026-04-22

...
...

A critical arbitrary file upload vulnerability in the Ninja Forms – File Upload Plugin (affecting versions up to 3.3.26) allows unauthenticated attackers to upload dangerous files (e.g., .php), use filename manipulation and path traversal to place files in sensitive locations, and potentially achieve remote code execution; Wordfence validated the PoC, the developer issued a partial fix on Feb 10 and a full patch on Mar 19 (v3.3.27), and administrators are strongly advised to update immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.