Immediate Remote Code Execution Risk in Ninja Forms File Uploads

Ninja Forms File Uploads premium add-on exposes about 90,000 WordPress sites to immediate remote code execution through unauthenticated PHP uploads. This is not a typical file upload flaw where attackers just store malicious files; attackers can execute code on the server as soon as they upload a crafted file. Standard patching responses miss that the attacker may already have persistent control over the entire site, not just the plugin. The critical vulnerability CVE-2026-0740 affects versions up to 3.3.26 of the File Uploads add-on. Wordfence has observed active exploitation, blocking over 3,600 attacks in 24 hours. The flaw allows attackers to bypass file type validation and path traversal protections, enabling them to place PHP files in the webroot and trigger remote code execution. This vulnerability carries a severity rating of 9.8 out of 10. This vulnerability demands immediate patching or taking the plugin offline for exposed sites. The risk is critical because the attack surface is a public upload form accessible without authentication, making the entire WordPress site a compromised asset. The scale of affected customers and active exploitation indicate this is a high-impact threat that will persist until fully remediated.

Part of the PlainSec briefing for 2026-05-02

Sources