CVE-2022-0888
CRITICALNinja Forms File Uploads Extension < 3.3.0 - Unauthenticated Arbitrary File Upload
Title source: llmDescription
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0
References (3)
Core 3
Core References
Exploit, Patch, Third Party Advisory
https://gist.github.com/Xib3rR4dAr/5f0accbbfdee279c68ed144da9cd8607
Third Party Advisory
https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0888
Scores
CVSS v3
9.8
EPSS
0.3939
EPSS Percentile
98.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-434
Status
published
Products (2)
ninjaforms/ninja_forms_file_uploads
< 3.3.0
SaturdayDrive/Ninja Forms - File Uploads
< 3.3.0
Published
Mar 23, 2022
Tracked Since
Feb 18, 2026