CVE-2026-0740Active Exploitation

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability was partially patched in version 3.3.25 and fully patched in version 3.3.27.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 22 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 70 mentions across 20 observed days

What's happening

  • Active exploitation reported across 22 signals
  • Exploit tool or code specified in 8 signals
  • PoC mentioned or linked in 15 signals
  • Patch or workaround mentioned in 29 signals
  • Technical details provided in 47 signals
  • Disclosure: 17 classified signals
  • Peaked 18d ago at 15 mentions (2026-04-07); latest day: 5
  • 70 total mentions across 20 days

Deep dive

Activity timeline70 mentions / 20d
0481115Mentions · 2026-04-06: 3Mentions · 2026-04-07: 15Mentions · 2026-04-08: 11Mentions · 2026-04-09: 3Mentions · 2026-04-10: 8Mentions · 2026-04-11: 1Mentions · 2026-04-13: 2Mentions · 2026-04-14: 3Mentions · 2026-04-16: 3Mentions · 2026-04-17: 2Mentions · 2026-04-18: 1Mentions · 2026-04-19: 3Mentions · 2026-04-21: 2Mentions · 2026-04-27: 1Mentions · 2026-04-29: 1Mentions · 2026-05-05: 1Mentions · 2026-05-06: 1Mentions · 2026-07-12: 2Mentions · 2026-07-13: 2Mentions · 2026-08-19: 5PoC Mentioned / Linked · 2026-04-07: 1PoC Mentioned / Linked · 2026-04-10: 3PoC Mentioned / Linked · 2026-04-14: 1PoC Mentioned / Linked · 2026-04-17: 2PoC Mentioned / Linked · 2026-04-27: 1PoC Mentioned / Linked · 2026-07-13: 2PoC Mentioned / Linked · 2026-08-19: 5Exploit Tool / Code · 2026-04-10: 3Exploit Tool / Code · 2026-04-14: 1Exploit Tool / Code · 2026-04-17: 1Exploit Tool / Code · 2026-04-27: 1Exploit Tool / Code · 2026-07-13: 2Active Exploitation · 2026-04-07: 3Active Exploitation · 2026-04-08: 4Active Exploitation · 2026-04-09: 2Active Exploitation · 2026-04-10: 3Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-04-14: 1Active Exploitation · 2026-04-16: 2Active Exploitation · 2026-04-18: 1Active Exploitation · 2026-05-05: 1Active Exploitation · 2026-05-06: 1Active Exploitation · 2026-07-12: 1Active Exploitation · 2026-08-19: 1Patch / Workaround · 2026-04-06: 2Patch / Workaround · 2026-04-07: 7Patch / Workaround · 2026-04-08: 5Patch / Workaround · 2026-04-09: 1Patch / Workaround · 2026-04-10: 5Patch / Workaround · 2026-04-13: 1Patch / Workaround · 2026-04-14: 1Patch / Workaround · 2026-04-16: 2Patch / Workaround · 2026-04-19: 1Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-05-05: 1Patch / Workaround · 2026-05-06: 1Patch / Workaround · 2026-07-13: 1Technical Details · 2026-04-06: 3Technical Details · 2026-04-07: 13Technical Details · 2026-04-08: 9Technical Details · 2026-04-09: 2Technical Details · 2026-04-10: 5Technical Details · 2026-04-13: 1Technical Details · 2026-04-14: 3Technical Details · 2026-04-16: 2Technical Details · 2026-04-17: 2Technical Details · 2026-04-19: 3Technical Details · 2026-05-05: 1Technical Details · 2026-05-06: 1Technical Details · 2026-07-13: 204-0604-0804-1004-1304-1604-1804-2104-2905-0607-1308-19
Signal classification7 categories
Active Exploitation
2028.6%
Disclosure
1724.3%
Patch
1115.7%
General
912.9%
PoC
912.9%
Exploit
34.3%
Referenced assets48 URLs
By indicator
Classification over time
DateTotalLabels
2026-04-063
Disclo****1Disclosure1Patch1
2026-04-0715
Active Exploitation3Disclosure8Patch4
2026-04-0811
Active Exploitation3Disclosure3General3Patch2
2026-04-093
Active Exploitation2General1
2026-04-108
Active Exploitation3Disclosure1Exploit1Patch2PoC1
2026-04-111
Active Exploitation1
2026-04-132
Active Exploitation1General1
2026-04-143
Disclosure2Exploit1
2026-04-163
Active Exploitation2General1
2026-04-172
PoC2
2026-04-181
Active Exploitation1
2026-04-193
Disclosure2Patch1
2026-04-212
General2
2026-04-271
PoC1
2026-04-291
Patch1
2026-05-051
Active Exploitation1
2026-05-061
Active Exploitation1
2026-07-122
Active Exploitation1General1
2026-07-132
Exploit1PoC1
2026-08-195
Active Exploitation1PoC4
Full discourse20 posts
  • Dark Web Informer@DarkWebInformer
    PoC

    ‼️CVE-2026-0740 - Ninja Forms File Uploads up to v3.3.26 - Unauthenticated Arbitrary File Upload PoC: https://github.com/0xgh057r3c0n/CVE-2026-0740 https://t.co/vADxEptzEF

    Post summary

    A proof‑of‑concept for CVE-2026-0740, which permits unauthenticated arbitrary file uploads in Ninja Forms versions up to 3.3.26, has been published on GitHub.

    141027817124.7K
    222.6K followersView on X
  • Ambionics Security@ambionics
    PoC

    🚨 Critical File Upload to RCE in @NinjaForms File Uploads @WordPress plugin (CVE-2026-0740)! Deep dive & PoC: 👉https://blog.lexfo.fr/ninja-forms-uploads_rce.html 🔍By @whattheslime from @Ambionics CTEM solution 🛡️Patch available (v3.3.27) — Update now! #WordPress #RCE #InfoSec #CyberSecurity #CVE

    Post summary

    The tweet announces a critical RCE in Ninja Forms via file upload, provides a PoC link, and reminds users to apply patch v3.3.27.

    226166336.5K
    2.0K followersView on X
  • dbugs@ptdbugs
    Exploit

    A PoC/exploit has been discovered for vulnerability CVE-2026-0740 PT ID: PT-2026-30693 Vendor: SaturdayDrive Product: Ninja Forms - File Uploads Description: The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability was partially patched in version 3.3.25 and fully patched in version 3.3.27. References: • https://dbugs.ptsecurity.com/vulnerability/PT-2026-30693 • https://github.com/ExDev994/CVE-2026-0740-mass

    Post summary

    A functional PoC/exploit for CVE‑2026‑0740 has been released, with a patch available in version 3.3.27; no evidence of active exploitation reported.

    06034124.0K
    3.4K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    5万サイト以上が使用するWordPressのNinja Forms – File Uploadプラグインに重大(Critical)な脆弱性。CVE-2026-0740はCVSSスコア9.8で、未認証の攻撃者が任意のファイルをアップロードすることでサイトを乗っ取り可能。ファイル拡張子チェックの不備。報奨金2,145ドル。 https://securityonline.info/ninja-forms-file-upload-rce-vulnerability-cve-2026-0740/

    Post summary

    The post announces a critical upload vulnerability (CVE‑2026‑0740) in Ninja Forms – File Upload with a CVSS of 9.8, enabling unauthenticated file uploads that can compromise sites, but it does not provide PoC, exploit code, or patch details.

    0632453.6K
    7.6K followersView on X
  • elhacker.NET@elhackernet
    Active Exploitation

    Explotación activa de CVE-2026-0740 en Ninja Forms File Uploads pone en riesgo miles de WordPress https://blog.elhacker.net/2026/04/explotacion-activa-de-cve-2026-0740-en.html

    Post summary

    The article announces that CVE-2026-0740 is actively being exploited in Ninja Forms File Uploads, jeopardizing thousands of WordPress sites, but it does not provide patches, technical specifics, or proof-of-concept details.

    0701632.0K
    140.8K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    General

    Saldırganların WordPress, Joomla gibi sistemlere saldırırken kullandığı CVE'ler : – CVE-2026-3844 (WordPress Breeze) – CVE-2026-48907 (Joomla JCE) Diğerleri: CVE-2026-1969, CVE-2026-3300, CVE-2026-0740, CVE-2026-6433, CVE-2025-7443, CVE-2025-7852, CVE-2025-12057, CVE-2020-36847 ve CVE-2020-25213

    Post summary

    The post simply lists CVE identifiers used by attackers against WordPress and Joomla, without providing technical details, proof of concept, or evidence of active exploitation or remediation.

    1301142.4K
    2.2K followersView on X
  • Wordfence@wordfence
    Disclo****

    50,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Ninja Forms - File Upload WordPress Plugin This critical vulnerability (CVE-2026-0740, CVSS 9.8) allows unauthenticated attackers to upload arbitrary files, potentially achieving remote code execution. Update to version 3.3.27. Thank you to researcher Sélim Lanouar (@whattheslime ), who earned a $2,145.00 bounty via the Wordfence Bug Bounty Program. https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin

    Post summary

    A critical arbitrary file upload flaw (CVE‑2026‑0740) affecting ~50,000 WordPress sites has been disclosed, carrying a CVSS score of 9.8; a patch to version 3.3.27 is available to prevent remote code execution.

    052741.6K
    8.2K followersView on X
  • Wordfence@wordfence
    Active Exploitation

    Attackers Actively Exploiting Critical Vulnerability in Ninja Forms – File Upload Plugin Estimated 50,000 WordPress sites are affected and should update to version 3.3.27 immediately. A critical vulnerability (CVE-2026-0740, CVSS 9.8) allows unauthenticated attackers to upload arbitrary files, including PHP backdoors, achieving remote code execution. Attackers began exploiting the flaw the same day it was disclosed, with the Wordfence Firewall blocking over 118,600 exploit attempts. Researcher Sélim Lanouar (@whattheslime) discovered and reported this vulnerability through the Wordfence Bug Bounty Program, earning a $2,145.00 bounty. https://www.wordfence.com/blog/2026/04/attackers-actively-exploiting-critical-vulnerability-in-ninja-forms-file-upload-plugin

    Post summary

    WordPress sites using Ninja Forms 3.3.26 are being actively targeted for a critical CVE‑2026‑0740 that permits unauthenticated file uploads and remote code execution; Wordfence reports >118,000 attempted exploits, and users should immediately upgrade to v3.3.27.

    13085459
    8.2K followersView on X
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-0740: Vulnerability in Ninja Forms WordPress plugin, 9.8 rating 🔥 The vulnerability allows unauthenticated attackers to upload arbitrary files to a vulnerable site and achieve remote code execution. 👉 https://nt.ls/rkM7h

    Post summary

    CVE-2026-0740 exposes a high‑severity remote code execution vulnerability in Ninja Forms via unauthenticated file upload; no evidence of exploitation or patch is provided.

    02032437
    7.3K followersView on X
  • Sélim Lanouar@whattheslime
    Exploit

    Check out my first article on @LexfoSecurite's blog about a critical vulnerability I found in @NinjaForms File Uploads! (CVE-2026-0740) Python exploit script also available on GitHub: 👉 https://github.com/whattheslime/CVE-2026-0740 @fofabot @HunterMapping

    Post summary

    The author announced a critical vulnerability (CVE‑2026‑0740) in NinjaForms file uploads and provided a Python exploit script on GitHub.

    01031403
    72 followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    Critical 9.8 flaw CVE-2026-0740 in Ninja Forms allows unauthenticated RCE via malicious file uploads. Update to version 3.3.27 immediately to protect your site. https://meterpreter.org/open-gate-how-a-9-8-severity-flaw-in-ninja-forms-grants-hackers-total-server-control/ https://t.co/rJlYrr8T5n

    Post summary

    The tweet announces a critical CVE-2026-0740 affecting Ninja Forms, highlights a severe RCE via file uploads, and urges users to update to version 3.3.27 to mitigate the risk.

    11020506
    12.3K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    『the malicious parameter also facilitates path traversal, allowing the file to be moved even to the webroot directory.』😨 CVE-2026-0740 50,000 WordPress Sites affected by Arbitrary File Upload Vulnerability in Ninja Forms – File Upload WordPress Plugin https://www.wordfence.com/blog/2026/04/50000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-ninja-forms-file-upload-wordpress-plugin/

    Post summary

    A path‑traversal flaw in Ninja Forms’ file‑upload feature permits arbitrary file placement and has affected approximately 50,000 WordPress sites.

    10003796
    6.8K followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    Critical arbitrary file upload flaw in Ninja Forms File Upload plugin (CVE-2026-0740, CVSS 9.8) affects 50,000 WordPress sites. Unauthenticated attackers can achieve RCE by uploading malicious PHP files. Update to version 3.3.27 immediately. #DFIR_Radar

    Post summary

    The post announces a critical file-upload vulnerability (CVE‑2026‑0740, CVSS 9.8) that can lead to arbitrary code execution on roughly 50,000 WordPress sites, and urges users to upgrade immediately to version 3.3.27.

    10021358
    1.7K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    A critical flaw (CVE-2026-0740) in Ninja Forms File Uploads plugin allows unauthenticated file uploads, including PHP scripts, leading to remote code execution. Patch version 3.3.27 addresses the issue. #WordPressSecurity #RemoteCodeExecution #France https://ift.tt/Cq0Ndtl

    Post summary

    CVE-2026-0740 is a remote code execution vulnerability in the Ninja Forms File Uploads plugin, and patch 3.3.27 has been released to mitigate the issue.

    00012211
    3.9K followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru
    General

    Two weeks on from CVE-2026-0740: if "which of my sites run plugin X below version Y?" takes more than 60 seconds to answer, you have a tooling problem, not a patching problem. https://mysites.guru/blog/ninja-forms-file-uploads-cve-2026-0740/?utm_source=twitter&utm_medium=social https://t.co/YSAFkaZQ5I

    Post summary

    The tweet refers to CVE-2026-0740 in the context of a blog post, but it does not provide any PoC, exploit code, active exploitation evidence, patch information, or technical details about the vulnerability.

    0002040
    2.5K followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru
    General

    Two weeks on from CVE-2026-0740, here's the evergreen takeaway: if you cannot answer "which of my WordPress sites are running plugin X below version Y" in under a minute, you cannot respond to plugin vulnerabilities at the speed attackers work. https://mysites.guru/blog/ninja-forms-file-uploads-cve-2026-0740/?utm_source=twitter&utm_medium=social https://t.co/6GphgfsQcM

    Post summary

    The post references CVE‑2026‑0740 but offers no PoC, exploit, patch, or technical detail; it merely stresses the need for rapid site‑inventory response.

    0002036
    2.5K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Critical file upload flaw in Ninja Forms WordPress plugin enables unauthenticated RCE. Mass exploitation began same day as disclosure with 118,600+ blocked attempts across 50,000 installations. Key technical details: • CVE-2026-0740, CVSS 9.8 - affects Ninja Forms File Upload ≤3.3.26, patched in 3.3.27 • Missing destination filename validation in NF_FU_AJAX_Controllers_Uploads::handle_upload function • Attackers upload disguised PHP webshells (PDF/JPG headers) + .htaccess files via path traversal • Exploitation via POST to /wp-admin/admin-ajax.php?action=nf_fu_upload with malicious multipart form data Attack methodology: • Valid file headers (PDF-1.4, GIF89a) bypass source validation while storing as .php extensions • Path traversal (../../) places shells in webroot outside upload directories • Webshells use php_uname(), shell_exec(), system() for reconnaissance and command execution • .htaccess modification forces .txt files to execute as PHP for steganography DFIR artifacts: • Check /wp-content/uploads/ and webroot for suspicious .php files with recent timestamps • Review access logs for nf_fu_upload action from IPs: 124[.]248[.]183[.]139, 152[.]42[.]221[.]239, 124[.]108[.]54[.]86 • Hunt multipart POST requests with mismatched Content-Type headers and destination filenames Hunt for recent PHP files in WordPress directories with minimal file sizes (<5KB) containing php_uname() or shell_exec() functions. #DFIR_Radar

    Post summary

    CVE-2026-0740 is a critical unauthenticated RCE in the Ninja Forms WordPress plugin, with mass exploitation observed on the day of disclosure and a patch already released.

    10010190
    1.3K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidad en complemento de WordPress ❗ CVE-2026-0740 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-complemento-de-wordpress-9/ https://t.co/alqpmOy5at

    Post summary

    The tweet briefly announces a WordPress plugin vulnerability (CVE-2026-0740) and points to an external link for details, but offers no technical, exploit, or mitigation information within the tweet itself.

    00020127
    6.7K followersView on X
  • Manage Multiple WordPress and Joomla Sites easily!@mysitesguru
    Disclosure

    CVE-2026-0740 in 50 words: Ninja Forms File Uploads checks the source filename but not the destination. Attacker uploads a .jpg, then supplies a POST param saying "save it as shell.php in the webroot". Plugin obeys. Around 50,000 WordPress sites affected. https://mysites.guru/blog/ninja-forms-file-uploads-cve-2026-0740/?utm_source=twitter&utm_medium=social

    Post summary

    The post discloses a vulnerability in Ninja Forms where upload checks the source filename only, letting attackers rename uploaded files to shell.php in the webroot, affecting roughly 50,000 WordPress sites.

    0001167
    2.5K followersView on X
  • nksistemas@nksistemas
    Active Exploitation

    Vulnerabilidad crítica en WordPress: explotación activa de CVE-2026-0740 en Ninja Forms File Uploads https://nksistemas.com/vulnerabilidad-critica-en-wordpress-explotacion-activa-de-cve-2026-0740-en-ninja-forms-file-uploads/

    Post summary

    An article reports that CVE-2026-0740 is actively exploited against Ninja Forms file uploads in WordPress, but does not provide patches, PoC details, or exploit code.

    01001118
    6.2K followersView on X

Explore more