HomeSecurityNinja Forms – File Upload: Vulnerability puts thousands of WordPress sites at risk

Ninja Forms – File Upload: Vulnerability puts thousands of WordPress sites at risk

A particularly dangerous security flaw has been discovered in the popular “Ninja Forms – File Upload” plugin for WordPress, exposing approximately 50,000 websites to full compromise. The vulnerability, recorded as CVE-2026-0740, has a CVSS score of 9.8/10, meaning it is very dangerous and requires immediate action from administrators and security professionals.

Ninja Forms – File Upload WordPress sites

The problem was discovered by researcher Sélim Lanouar, who was awarded the prize for his discovery. It is a bug that allows unauthorized file uploads, allowing any internet user to upload malicious content to a website without requiring any form of identification.

Ninja Forms – File Upload: How the vulnerability works

This plugin is designed to handle files uploaded by users via forms, internally using the handle_upload() function. During the save process, the files are moved to the final folder via move_uploaded_file(), however, a critical omission is found there.

See also: Storm-1175: Zero-day exploit for Medusa ransomware deployment

Although a basic file type check is performed, the extension in the final file name is not properly validated . At the same time, proper name sanitization is absent, leaving room for techniques such as path traversal. In this way, an attacker can bypass the restrictions and upload malicious .php files to critical directories on the server.

From simple upload to full control

Exploiting the vulnerability could lead to remote code execution (RCE), one of the most serious scenarios in cybersecurity. Through a webshell, the attacker gains full access to the system, with the ability to execute commands directly on the server.

Ninja Forms – File Upload: Vulnerability puts thousands of WordPress sites at risk

The impacts are extensive: from data theft and content corruption, to malware insertion and redirection of users to phishing or spam websites. In some cases, compromised servers are also used as launching pads for attacks on other targets, reinforcing the cybercrime chain.

See also: Flowise AI Platform: Critical vulnerability under active exploitation

Thousands of websites exposed

The vulnerability affects all versions of the plugin up to 3.3.26, which explains the wide range of potentially exposed websites. The issue was first reported by Wordfence, which immediately firewall protection for its subscribers and then extended coverage to free users.

The plugin's creators reacted relatively quickly, initially releasing a partial fix and eventually a full fix in version 3.3.27, which was released on March 19, 2026.

What administrators should do immediately

Upgrading to the latest available version is the only reliable solution to prevent exploitation of the vulnerability. Since the attack does not require user authentication, unpatched sites are easy targets for automated bots that scan the internet.

See also: Apache Traffic Server: Vulnerabilities allow DoS attacks

At the same time, experts recommend additional measures, such as restricting write permissions to folders, using a web application firewall, and regularly checking files for suspicious activity.

Ninja Forms – File Upload: Vulnerability puts thousands of WordPress sites at risk

The bigger picture of plugin security

This incident highlights a perennial problem in the ecosystem WordPress: the reliance on third-party plugins. While they offer flexibility and functionality, they are often the weakest point in security.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

As attacks become increasingly automated and massive, the need for regular updates and proactive security becomes more imperative than ever. For website administrators, the Ninja Forms case serves as yet another clarion call for constant vigilance.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr/politiki-syntaxis/
Member of the SecNews Editorial Team. Covers software vulnerabilities, data breaches, cyberattacks and technology developments. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS