Critical Vulnerability Discovered in Ninja Forms Plugin, Urgent Action Required
A severe security flaw in the Ninja Forms File Upload add-on for WordPress has been identified, allowing malicious users to upload arbitrary files and potentially execute harmful code. Known as CVE-2026-0740, this vulnerability has a critical severity rating of 9.8 out of 10 and is currently being exploited in the wild.
Over 600,000 users rely on Ninja Forms, with around 90,000 using the vulnerable File Upload extension. This issue poses significant risks, including unauthorized access to websites and complete site takeovers.
Security firm Wordfence reported blocking more than 3,600 attempted attacks in just one day. Users are strongly urged to upgrade to the latest version, 3.3.27, to mitigate risks.
Risk Level: High. To protect yourself, ensure your Ninja Forms plugin is updated and monitor your site for unusual activity.
Source: View Original Report
