The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0
Metrics
Affected Vendors & Products
References
History
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Ninja Forms - File Uploads Extension <= 3.3.0 - Arbitrary File Upload |
Status: PUBLISHED
Assigner: Wordfence
Published: 2022-03-23T19:46:51.000Z
Updated: 2026-04-08T17:32:10.389Z
Reserved: 2022-03-08T00:00:00.000Z
Link: CVE-2022-0888
No data.
Status : Modified
Published: 2022-03-23T20:15:10.470
Modified: 2026-04-08T19:17:49.300
Link: CVE-2022-0888
No data.