Vulnary
← back to the feed
Critical· 9.6

CVE-2026-57784

A critical vulnerability in the Ninja Forms File Uploads Extension allows attackers to perform cross‑site request forgery without authentication. The flaw can be triggered by a malicious link and can lead to unauthorized file uploads, data loss, or other impacts. The vulnerability is rated CVSS 9.6.

publishedJul 23, 2026
last modifiedJul 23, 2026
sourcesNVD
severity · cvss
9.6
critical · how bad it is
exploitation · epss
<1%
3th percentile · chance of exploitation in 30 days
(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →
auto-deletes from the system
counting…on Sep 6, 2026

No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.

01

Who is affected

Ninja Forms File Uploads Extension versions 3.3.26 and earlier, used in WordPress sites.

02

Real-world impact

An attacker could trick a logged‑in user into uploading malicious files or performing other actions, potentially compromising the site or its data.

03

Why this severity

The CVSS score of 9.6 reflects that the flaw requires no special privileges, can be triggered by a user with a browser, and changes the scope of the system, giving attackers full compromise of confidentiality, integrity, and availability.

04

What to do about it

no official fix yet
interim mitigations
  • Disable or remove the Ninja Forms File Uploads Extension until an updated version is released.
  • Restrict access to the file upload functionality to trusted users only.

No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.

No fix documented in sources

05

Timeline

06

How it’s attacked

Attack vectorNetwork (remote)
Attack complexityLow
Privileges requiredNone
User interactionRequired
ScopeChanged
Confidentiality impactHigh
Integrity impactHigh
Availability impactHigh
07

References & advisories

(ai-assisted) A model wrote this summary from the official data, so double-check it against the source before you act on it. Read the official advisory →