CVE-2026-0740
CVSS 9.8 CRITICAL: the Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type… EPSS 63% (99th percentile).
Vulnerabilities & Exploits · Web App Attack
Ninja Forms File Uploads premium add-on exposes about 90,000 WordPress sites to immediate remote code execution through unauthenticated PHP uploads. This is not a typical file upload flaw where attackers just store malicious files; attackers can execute code on the server as soon as they upload a crafted file. Standard patching responses miss that the attacker may already have persistent control over the entire site, not just the plugin.
The critical vulnerability CVE-2026-0740 affects versions up to 3.3.26 of the File Uploads add-on. Wordfence has observed active exploitation, blocking over 3,600 attacks in 24 hours. The flaw allows attackers to bypass file type validation and path traversal protections, enabling them to place PHP files in the webroot and trigger remote code execution. This vulnerability carries a severity rating of 9.8 out of 10.
This vulnerability demands immediate patching or taking the plugin offline for exposed sites. The risk is critical because the attack surface is a public upload form accessible without authentication, making the entire WordPress site a compromised asset. The scale of affected customers and active exploitation indicate this is a high-impact threat that will persist until fully remediated.
3 sources · Apr 8
CVSS 9.8 CRITICAL: the Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type… EPSS 63% (99th percentile).
Infosecurity Magazine
Critical Vulnerability in Ninja Forms Exposes WordPress Sites
Ninja Forms File Upload RCE via unauthenticated arbitrary file upload; update to 3.3.27 immediately
originalSecurityWeek
Hackers Targeting Ninja Forms Vulnerability That Exposes WordPress Sites to Takeover
The vulnerability allows hackers to upload arbitrary files to a site’s server and achieve remote code execution.
originalBleepingComputer
Hackers exploit critical flaw in Ninja Forms WordPress plugin
A critical vulnerability in the Ninja Forms File Uploads premium add-on for WordPress allows uploading arbitrary files without authentication, which can lead to remote code execution.
originalPart of the PlainSec briefing for 2026-04-13
Every edition of this story: Immediate Remote Code Execution Risk in Ninja Forms File Uploads