A critical vulnerability in the WordPress plugin Ninja Forms – File Uploads has exposed more than 50,000 sites to unauthenticated arbitrary file upload, with security researchers and CSIRT.SK reporting active exploitation in the wild. Tracked as CVE-2026-0740, the flaw affects versions 3.3.26 and earlier and stems from insufficient validation of uploaded file types, file extensions, and file paths in NF_FU_AJAX_Controllers_Uploads::handle_upload, allowing attackers to upload malicious files, including PHP scripts.
Successful exploitation can lead to remote code execution and full site compromise, giving attackers a path to persistent access and broader server takeover. Defenders are urged to update immediately to version 3.3.27 or later and review affected WordPress installations for unauthorized uploads or filesystem changes, as public reporting indicates the vulnerable plugin was deployed on tens of thousands of websites at the time of disclosure.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
CSIRT.SK reported that CVE-2026-0740, a critical arbitrary file upload vulnerability in the WordPress plugin Ninja Forms – File Uploads affecting versions 3.3.26 and earlier, was being actively exploited in the wild. The flaw could allow unauthenticated attackers to upload arbitrary files, including PHP scripts, leading to possible remote code execution and full site compromise.
Wordfence published reporting that roughly 50,000 WordPress sites were affected by an arbitrary file upload vulnerability in the Ninja Forms File Upload plugin. The report concerns the same vulnerability, CVE-2026-0740, in the WordPress plugin ecosystem.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.