CVE-2026-57784
A critical vulnerability in the Ninja Forms File Uploads Extension allows attackers to perform cross‑site request forgery without authentication. The flaw can be triggered by a malicious link and can lead to unauthorized file uploads, data loss, or other impacts. The vulnerability is rated CVSS 9.6.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Ninja Forms File Uploads Extension versions 3.3.26 and earlier, used in WordPress sites.
Real-world impact
An attacker could trick a logged‑in user into uploading malicious files or performing other actions, potentially compromising the site or its data.
Why this severity
The CVSS score of 9.6 reflects that the flaw requires no special privileges, can be triggered by a user with a browser, and changes the scope of the system, giving attackers full compromise of confidentiality, integrity, and availability.
What to do about it
- ›Disable or remove the Ninja Forms File Uploads Extension until an updated version is released.
- ›Restrict access to the file upload functionality to trusted users only.
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources