Skip to content

Known CVE

Ninja Forms File Uploads <= 3.3.26 - Arbitrary File Upload

Ninja Forms File Uploads plugin for WordPress versions up to and including 3.3.26 is vulnerable to unauthenticated arbitrary file upload which could lead to remote code execution.

CVE-2026-0740

Critical2026CVSS 9.8CWE-434

cve2026 · wordpress · wp · wp-plugin · ninja-forms-uploads · file-upload · rce · vkev

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website