TopVuln

High-risk vulnerability digests

CVE-2026-0740

  • CRITICAL

Details

CVSS v3
9.8
NVD published
2026-04-07 05:16:06
EPSS
0.1% probability · 26.1th percentile — 2026-05-12
Affected versions
Ninja Forms File Uploads plugin for WordPress <= 3.3.26
Summary
This vulnerability stems from missing file type validation in the upload handler of the Ninja Forms File Uploads WordPress plugin. It allows unauthenticated remote attackers to upload arbitrary files to the affected web server. This can lead to full remote code execution on the target host.
Remediation
Update the Ninja Forms File Uploads plugin to version 3.3.27 or later immediately. Until the update can be applied, block unauthenticated access to the plugin's upload endpoint via a web application firewall.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.