Skip to content
Critical Vulnerability in Ninja Forms Plugin Exposes 50,000 WordPress Sites to RCE

Critical Vulnerability in Ninja Forms Plugin Exposes 50,000 WordPress Sites to RCE

First seen 7 Apr 2026, 08:01 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •April 8, 2026 at 07:33 UTC
  • •CVE-2026-0740 allows arbitrary file uploads without authentication.
  • •Over 50,000 WordPress sites using Ninja Forms are vulnerable to exploitation.
  • •A complete fix was released on March 19, 2026; users must upgrade immediately.

A critical vulnerability (CVE-2026-0740) in the Ninja Forms File Uploads plugin for WordPress allows unauthenticated attackers to upload arbitrary files, potentially leading to remote code execution. This flaw, with a CVSS score of 9.8, affects versions up to 3.3.26 and has been actively exploited, with over 3,600 attacks blocked in the last 24 hours by Wordfence. Approximately 50,000 websites utilizing this plugin are at risk, as the vulnerability stems from inadequate validation of file types during upload. Discovered by researcher Sélim Lanouar, the flaw was reported on January 8, 2026, and a complete fix was released on March 19, 2026. Users are strongly advised to upgrade to the latest version to mitigate risks. The potential impact includes complete site takeover and deployment of web shells.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 186d ago How this analysis works

Timeline

2026-01-08
Vulnerability discovered and reported to Wordfence
2026-02-10
Partial fix released after patch reviews
2026-03-19
Complete fix released in version 3.3.27
2026-04-07
CVE-2026-0740 published, active exploitation reported

More articles in this cluster (6)

Following this threat?

Track CVE-2026-0740 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed