Ninja Forms Flaw Exposes 50,000 WordPress Sites
A critical ninja forms flaw in the WordPress plugin has exposed approximately 50,000 websites to potential takeover. This vulnerability, identified as CVE-2026-0740, has been assigned a severity score of 9.8, highlighting the urgent need for action from site administrators. Discovered by security researcher Sélim Lanouar, the flaw permits unauthorized file uploads, which can lead to Remote Code Execution (RCE).
The issue arises from ineffective validation of file types and extensions in the Ninja Forms File Upload addon’s handle_upload() function, allowing malicious PHP files to infiltrate and compromise web servers. If exploited, attackers can execute commands on the server, leading to data theft or further attacks. Versions up to 3.3.26 of the plugin are affected. Wordfence provided firewall updates for users, and the plugin’s developers issued a comprehensive patch in version 3.3.27 on March 19, 2026. Website managers must urgently update to the latest version to mitigate risks.
For additional details, read the full article at: https://cybersecuritynews.com/50000-wordpress-sites-exposed/
