Description
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used without validation to attach a file to the form's notification email (arbitrary file read), to write fetched content (arbitrary file write, leading to remote code execution when the external store is configured), and in a scheduled deletion (arbitrary file deletion). This makes it possible for unauthenticated attackers to read, write, or delete arbitrary files on the server. Exploitation requires the site to use the plugin's External File Upload (Amazon S3) action; the read variant additionally requires a form Email action configured to attach the uploaded file.
Published: 2026-10-02
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability in the Ninja Forms – File Uploads plugin allows attackers to supply a crafted file path during the external Amazon S3 upload process. The plugin stores this path without validation and later uses it for email attachment, writing, and deletion operations. This flaw results in arbitrary file read, write, or delete, and when the external store is configured can lead to remote code execution.

Affected Systems

WordPress sites that have the Ninja Forms – File Uploads plugin version 3.3.34 or earlier installed. The affected plugin is distributed by SaturdayDrive under the Vendor: SaturdayDrive, Product: Ninja Forms – File Uploads, all releases up to and including 3.3.34 are vulnerable.

Risk and Exploitability

The CVSS score of 8.1 indicates high impact, though no EPSS score is available and the flaw is not yet listed in the CISA KEV catalog. Attackers do not need credentials; they can exploit the flaw via the public form when the External File Upload (Amazon S3) action is enabled and, for arbitrary file read, when a form Email action is configured to attach uploaded files. The lack of input validation means a malicious path can target any writable, readable, or deletable file on the server, potentially achieving remote code execution if the external storage is active.

Generated by OpenCVE AI on October 2, 2026 at 06:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Ninja Forms – File Uploads plugin to version 3.3.35 or later.
  • If an upgrade is not immediately possible, disable the External File Upload (Amazon S3) action for all forms or restrict it to trusted users.
  • Remove or reconfigure any form Email actions that attach uploaded files until the plugin is patched.

Generated by OpenCVE AI on October 2, 2026 at 06:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 05:45:00 +0000

Type Values Removed Values Added
Description The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used without validation to attach a file to the form's notification email (arbitrary file read), to write fetched content (arbitrary file write, leading to remote code execution when the external store is configured), and in a scheduled deletion (arbitrary file deletion). This makes it possible for unauthenticated attackers to read, write, or delete arbitrary files on the server. Exploitation requires the site to use the plugin's External File Upload (Amazon S3) action; the read variant additionally requires a form Email action configured to attach the uploaded file.
Title Ninja Forms - File Uploads <= 3.3.34 - Unauthenticated Arbitrary File Upload
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-02T05:30:15.764Z

Reserved: 2026-09-16T20:19:51.864Z

Link: CVE-2026-92820

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T06:16:43.197

Modified: 2026-10-02T13:18:55.613

Link: CVE-2026-92820

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T06:30:18Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type