Impact
The vulnerability in the Ninja Forms – File Uploads plugin allows attackers to supply a crafted file path during the external Amazon S3 upload process. The plugin stores this path without validation and later uses it for email attachment, writing, and deletion operations. This flaw results in arbitrary file read, write, or delete, and when the external store is configured can lead to remote code execution.
Affected Systems
WordPress sites that have the Ninja Forms – File Uploads plugin version 3.3.34 or earlier installed. The affected plugin is distributed by SaturdayDrive under the Vendor: SaturdayDrive, Product: Ninja Forms – File Uploads, all releases up to and including 3.3.34 are vulnerable.
Risk and Exploitability
The CVSS score of 8.1 indicates high impact, though no EPSS score is available and the flaw is not yet listed in the CISA KEV catalog. Attackers do not need credentials; they can exploit the flaw via the public form when the External File Upload (Amazon S3) action is enabled and, for arbitrary file read, when a form Email action is configured to attach uploaded files. The lack of input validation means a malicious path can target any writable, readable, or deletable file on the server, potentially achieving remote code execution if the external storage is active.
OpenCVE Enrichment