CVE-2022-0888
CRITICALNinjaforms Ninja Forms File Uploads < 3.3.0 - Unrestricted File Upload
Title source: ruleDescription
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0
References (3)
Core 3
Core References
Exploit, Patch, Third Party Advisory
https://gist.github.com/Xib3rR4dAr/5f0accbbfdee279c68ed144da9cd8607
Third Party Advisory
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0888
Scores
CVSS v3
9.8
EPSS
0.0930
EPSS Percentile
92.8%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (2)
ninjaforms/ninja_forms_file_uploads
< 3.3.0
SaturdayDrive/Ninja Forms - File Uploads
< 3.3.0
Published
Mar 23, 2022
Tracked Since
Feb 18, 2026