CVE-2026-0740
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability was partially patched in version 3.3.25 and fully patched in version 3.3.27.
- Affected products
- Ninja Forms - File Uploads
- Fix
- Available
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 62.9% (99th percentile)
- Weakness
- CWE-434
- NVD status
- Deferred
- Published
- 2026-04-07
CVE-2026-0740 at NVD
14 known exploits for CVE-2026-0740
Proof-of-concept code and exploit modules indexed by Sploitus
CVE-2026-0740
ninja-form-exploit
CVE-2026-0740
CVE-2026-0740-mass
CVE-2026-0740-upload-template
Exploit for CVE-2026-0740
Exploit for CVE-2026-0740
Exploit for CVE-2026-0740
Mephisto
Ninja Forms Uploads - Unauthenticated PHP File Upload
π WordPress Ninja Forms - File Uploads 3.3.26 Shell Upload / Traversal
Exploit for CVE-2026-0740
Exploit for CVE-2026-0740
Exploit for CVE-2026-0740