Title: Critical Vulnerability Discovered in Ninja Forms Plugin for WordPress
Introduction:
A serious security flaw has been identified in the Ninja Forms – File Upload plugin, affecting around 50,000 WordPress sites. Discovered by researcher Sélim Lanouar and reported on January 8, 2026, this vulnerability allows unauthorized users to upload malicious files, potentially leading to remote code execution.
Vulnerability Explanation:
The issue stems from inadequate file type validation in versions up to 3.3.26 of the plugin. This oversight enables attackers to upload arbitrary files, including harmful scripts.
Affected Component:
Ninja Forms – File Upload plugin, versions 3.3.26 and earlier.
Impact:
Exploitation of this vulnerability could allow attackers full control over affected sites, posing a significant risk to site integrity and security.
Fix:
Users are urged to update to the latest version (3.3.27), which fully addresses the vulnerability.
Risk Level:
The vulnerability has been rated as critical, with a CVSS score of 9.8. Immediate action is recommended to protect your site.
Source: View Original Report
