Vulnerabilities & Exploits · Web App Attack

Immediate Remote Code Execution Risk in Ninja Forms File Uploads

Ninja Forms File Uploads premium add-on exposes about 90,000 WordPress sites to immediate remote code execution through unauthenticated PHP uploads. This is not a typical file upload flaw where attackers just store malicious files; attackers can execute code on the server as soon as they upload a crafted file. Standard patching responses miss that the attacker may already have persistent control over the entire site, not just the plugin.

The critical vulnerability CVE-2026-0740 affects versions up to 3.3.26 of the File Uploads add-on. Wordfence has observed active exploitation, blocking over 3,600 attacks in 24 hours. The flaw allows attackers to bypass file type validation and path traversal protections, enabling them to place PHP files in the webroot and trigger remote code execution. This vulnerability carries a severity rating of 9.8 out of 10.

This vulnerability demands immediate patching or taking the plugin offline for exposed sites. The risk is critical because the attack surface is a public upload form accessible without authentication, making the entire WordPress site a compromised asset. The scale of affected customers and active exploitation indicate this is a high-impact threat that will persist until fully remediated.

3 sources · Apr 8

CVE-2026-0740

NVD KEV

CVSS 9.8 CRITICAL: the Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type… EPSS 63% (99th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-04-08

Every edition of this story: Immediate Remote Code Execution Risk in Ninja Forms File Uploads

More from today