Hackers exploit critical flaw in Ninja Forms WordPress plugin

The Ninja Forms File Uploads premium add-on for WordPress has a serious flaw that permits the uploading of any file without authentication, potentially resulting in remote code execution.

The vulnerability, known as CVE-2026-0740, is actively being used in attacks. Defiant, a WordPress security business, claims that in the last day, its Wordfence firewall stopped over 3,600 attempts.

Ninja Forms, a well-known WordPress form builder with over 600,000 downloads, uses a drag-and-drop interface to enable users to create forms without knowing any code. 90,000 users are served by its File Upload extension, which is part of the same package.

Ninja Forms File Upload versions up to 3.3.26 are vulnerable to CVE-2026-0740, which has a critical severity rating of 9.8 out of 10.

Researchers at Wordfence claim that the vulnerability is brought about by a failure to validate file types and extensions on the destination filename, which permits an unauthorized attacker to upload any file—including PHP scripts—and to change filenames to allow path traversal read more about Hackers exploit critical flaw in Ninja Forms WordPress plugin.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *