A particularly dangerous security flaw has been discovered in the popular “Ninja Forms – File Upload” plugin for WordPress, exposing approximately 50,000 websites to full compromise. The vulnerability, recorded as CVE-2026-0740, has a CVSS score of 9.8/10, meaning it is very dangerous and requires immediate action from administrators and security professionals.

The problem was discovered by researcher Sélim Lanouar, who was awarded the prize for his discovery. It is a bug that allows unauthorized file uploads, allowing any internet user to upload malicious content to a website without requiring any form of identification.
Ninja Forms – File Upload: How the vulnerability works
This plugin is designed to handle files uploaded by users via forms, internally using the handle_upload() function. During the save process, the files are moved to the final folder via move_uploaded_file(), however, a critical omission is found there.
See also: Storm-1175: Zero-day exploit for Medusa ransomware deployment
Although a basic file type check is performed, the extension in the final file name is not properly validated . At the same time, proper name sanitization is absent, leaving room for techniques such as path traversal. In this way, an attacker can bypass the restrictions and upload malicious .php files to critical directories on the server.
From simple upload to full control
Exploiting the vulnerability could lead to remote code execution (RCE), one of the most serious scenarios in cybersecurity. Through a webshell, the attacker gains full access to the system, with the ability to execute commands directly on the server.

The impacts are extensive: from data theft and content corruption, to malware insertion and redirection of users to phishing or spam websites. In some cases, compromised servers are also used as launching pads for attacks on other targets, reinforcing the cybercrime chain.
See also: Flowise AI Platform: Critical vulnerability under active exploitation
Thousands of websites exposed
The vulnerability affects all versions of the plugin up to 3.3.26, which explains the wide range of potentially exposed websites. The issue was first reported by Wordfence, which immediately firewall protection for its subscribers and then extended coverage to free users.
The plugin's creators reacted relatively quickly, initially releasing a partial fix and eventually a full fix in version 3.3.27, which was released on March 19, 2026.
What administrators should do immediately
Upgrading to the latest available version is the only reliable solution to prevent exploitation of the vulnerability. Since the attack does not require user authentication, unpatched sites are easy targets for automated bots that scan the internet.
See also: Apache Traffic Server: Vulnerabilities allow DoS attacks
At the same time, experts recommend additional measures, such as restricting write permissions to folders, using a web application firewall, and regularly checking files for suspicious activity.

The bigger picture of plugin security
This incident highlights a perennial problem in the ecosystem WordPress: the reliance on third-party plugins. While they offer flexibility and functionality, they are often the weakest point in security.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
As attacks become increasingly automated and massive, the need for regular updates and proactive security becomes more imperative than ever. For website administrators, the Ninja Forms case serves as yet another clarion call for constant vigilance.
