






















Threat Insight
A critical security vulnerability has been identified in the Ninja Forms – File Upload plugin for WordPress, affecting an estimated 50,000 active websites.
The vulnerability is an arbitrary file upload flaw caused by insufficient validation of destination filenames during the upload process. An attacker does not need valid credentials to exploit the issue, making it particularly high risk for publicly accessible WordPress sites using the affected plugin[1].
If exploited, this vulnerability could allow attackers to achieve remote code execution on the affected server, upload webshells or other malicious files and potentially gain full control of the WordPress site and its underlying environment.
CVE-2026-0740
Ninja Forms – File Upload plugin versions up to and including 3.3.26.
A proof-of-concept exploit is publicly available[1].
Truesec recommends that you apply mitigations based on vendor instructions[1]:
[1] https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/
[2] https://www.cve.org/CVERecord?id=CVE-2026-0740
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。