Description
Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
Published: 2026-07-23
Score: 9.6 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated CSRF flaw exists in the Ninja Forms File Uploads Extension plugin up to version 3.3.26. This weakness allows a remote actor to craft a request that, when executed with the context of a logged‑in administrator, triggers a file upload. The consequence is the ability to upload arbitrary files, potentially including executable code, which would compromise the integrity and confidentiality of the WordPress installation. The vulnerability is a classic CSRF (CWE‑352).

Affected Systems

WordPress sites that have the Ninja Forms File Uploads Extension plugin version 3.3.26 or earlier. The flaw resides in the plugin's file upload endpoint and does not affect other WordPress components or plugins.

Risk and Exploitability

The CVSS score of 9.6 places the vulnerability in the Critical severity range. Despite this high severity, the EPSS score is less than 1 %, indicating a very low probability of exploitation at the time of analysis, and the flaw is not listed in the CISA KEV catalog. Attacks would likely rely on social engineering to lure an authenticated administrator into visiting a crafted URL, after which the attack capitalizes on the missing CSRF token validation to execute the file upload. No additional authentication or privileges are required beyond the victim’s legitimate session.

Generated by OpenCVE AI on August 4, 2026 at 15:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Ninja Forms File Uploads Extension plugin to the latest publicly available version that includes the CSRF fix.
  • If an update cannot be applied immediately, disable the file upload feature via plugin settings or restrict access to the upload endpoint using web‑application firewall rules.
  • Enable detailed logging of file upload actions and monitor for suspicious uploads. Alert administrators to any unauthorized file upload activity so that potential compromises can be investigated promptly.

Generated by OpenCVE AI on August 4, 2026 at 15:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 02 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
First Time appeared Ninjaforms
Ninjaforms ninja Forms File Uploads
Wordpress
Wordpress wordpress
Vendors & Products Ninjaforms
Ninjaforms ninja Forms File Uploads
Wordpress
Wordpress wordpress

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 11:45:00 +0000

Type Values Removed Values Added
Description Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
Title WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Request Forgery (CSRF) vulnerability
Weaknesses CWE-352
References
Metrics cvssV3_1

{'score': 9.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H'}


Subscriptions

Ninjaforms Ninja Forms File Uploads
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-07-23T15:11:48.466Z

Reserved: 2026-06-25T08:04:53.458Z

Link: CVE-2026-57784

cve-icon Vulnrichment

Updated: 2026-07-23T15:11:42.123Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T12:18:30.407

Modified: 2026-07-23T16:17:28.043

Link: CVE-2026-57784

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:30:06Z

Weaknesses
  • CWE-352

    Cross-Site Request Forgery (CSRF)