VYPR

Ninja Forms File Uploads

by WordPress

CVEs (4)

  • CVE-2026-0740CriApr 7, 2026
    risk 0.68cvss 9.8epss 0.58

    The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for…

  • CVE-2024-1596HigSep 7, 2024
    risk 0.47cvss 7.2epss 0.00

    The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Stored Cross-Site Scripting via an uploaded file (e.g. RTX file) in all versions up to, and including, 3.3.16 due to insufficient input sanitization and output escaping. This makes it possible for…

  • CVE-2026-12557Jul 3, 2026
    risk 0.00cvss epss 0.00

    The Ninja Forms - File Uploads plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 3.3.29. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated…

  • CVE-2026-13369Jul 2, 2026
    risk 0.00cvss epss 0.00

    The Ninja Forms - File Uploads plugin for WordPress is vulnerable to Arbitrary File Read via the attach_files() function in versions up to, and including, 3.3.29. This is due to the get_files_for_attachment() function accepting a raw attacker-controlled 'files' array when the…