CVE-2026-0740

CRITICAL EXPLOITED NUCLEI

Ninja Forms - File Upload <= 3.3.26 - Unauthenticated Arbitrary File Upload

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-0740 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 13 public exploits from researchers including selim.lanouar, adminlove520, MadExploits. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated PHP file upload vulnerability in Ninja Forms Uploads (CVE-2026-0740). It uploads a webshell by leveraging a nonce generation flaw and path traversal in the file upload mechanism.

Description

The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'NF_FU_AJAX_Controllers_Uploads::handle_upload' function in all versions up to, and including, 3.3.26. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server which may make remote code execution possible. Note: The vulnerability was partially patched in version 3.3.25 and fully patched in version 3.3.27.

Exploits (13)

exploitdb WORKING POC
by selim.lanouar · bashwebappsmultiple
https://www.exploit-db.com/exploits/52560

This exploit demonstrates an unauthenticated PHP file upload vulnerability in Ninja Forms Uploads (CVE-2026-0740). It uploads a webshell by leveraging a nonce generation flaw and path traversal in the file upload mechanism.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ninja Forms Uploads 3.3.24
No auth needed
Prerequisites: WordPress with Ninja Forms Uploads plugin installed · Access to wp-admin/admin-ajax.php
mistral-large-3 · analyzed May 14, 2026 Full analysis →
github WORKING POC 3 stars
by adminlove520 · pythonpoc
https://github.com/adminlove520/CVE-Poc_All_in_One/tree/main/2026/CVE-2026-0740

This repository contains a functional exploit for CVE-2026-0740, an unauthenticated arbitrary file upload vulnerability in Ninja Forms - File Upload plugin for WordPress. The exploit automates the process of obtaining a nonce, uploading a disguised PHP shell, and renaming it to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ninja Forms - File Upload plugin for WordPress <= 3.3.26
No auth needed
Prerequisites: WordPress site with vulnerable Ninja Forms - File Upload plugin · list.txt file containing target URLs
mistral-large-3 · analyzed May 04, 2026 Full analysis →
github SCANNER 1 stars
by MadExploits · pythonremote
https://github.com/MadExploits/ninja-form-exploit

This repository contains a multi-threaded Python scanner for CVE-2026-0740, a path traversal vulnerability in the Ninja Forms File Uploads plugin for WordPress. The script detects vulnerable instances by fuzzing directories (1-100) and verifying unauthorized file uploads via crafted AJAX requests with path traversal payloads.

Classification
Scanner 98%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Ninja Forms File Uploads plugin (WordPress)
No auth needed
Prerequisites: WordPress site with Ninja Forms File Uploads plugin installed · Target must expose `/wp-admin/admin-ajax.php` endpoint · Directory structure `wp-content/uploads/ninja-forms/{1-100}/` must exist
mistral-large-3 · analyzed Jul 14, 2026 Full analysis →
github WORKING POC
by ExDev994 · pythonremote
https://github.com/ExDev994/CVE-2026-0740-mass

This repository contains a functional exploit for CVE-2026-0740, an unauthenticated arbitrary file upload vulnerability in the Ninja Forms File Uploads WordPress plugin (<= 3.3.26). The exploit leverages path traversal and extension manipulation to upload malicious files (e.g., PHP webshells) and achieve remote code execution (RCE).

Classification
Working Poc 98%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ninja Forms File Uploads WordPress plugin <= 3.3.26
No auth needed
Prerequisites: Target must have Ninja Forms and Ninja Forms File Uploads plugin (<= 3.3.26) installed and active · Attacker must provide a valid webshell/payload file for upload
mistral-large-3 · analyzed Jul 11, 2026 Full analysis →
github SUSPICIOUS
by HORKimhab · poc
https://github.com/HORKimhab/poc-cve-collection/tree/main/2026/0xxx/CVE-2026-0740.md

The repository contains only a markdown file with a vulnerability description and external links to other GitHub repositories or encrypted backups, but no actual exploit code or technical analysis. The README lacks depth and points to external sources without providing functional PoC code.

Classification
Suspicious 98%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: Ninja Forms - File Upload plugin for WordPress <= 3.3.26
No auth needed
Prerequisites: Access to a vulnerable WordPress site with Ninja Forms - File Uploads plugin <= 3.3.26
mistral-large-3 · analyzed Jul 10, 2026 Full analysis →
github SUSPICIOUS
by BastianXploited · poc
https://github.com/BastianXploited/CVE-2026-0740-mass

The repository contains a ZIP file with obfuscated and non-functional code fragments, alongside a README with no technical details about the vulnerability. The ZIP file appears to contain corrupted or intentionally obfuscated Python and PHP files, with no clear exploit logic or vulnerability explanation.

Classification
Suspicious 95%
Attack Type
Other
Complexity
Unknown
Reliability
Theoretical
Target: unspecified
No auth needed
mistral-large-3 · analyzed Jul 03, 2026 Full analysis →
nomisec WORKING POC
by a24ac1 · poc
https://github.com/a24ac1/CVE-2026-0740

This repository contains a functional exploit for CVE-2026-0740, targeting a vulnerability in Ninja Forms (WordPress plugin). The exploit uploads a malicious PHP shell by abusing the file upload functionality via admin-ajax.php, leveraging a nonce retrieval mechanism.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ninja Forms (WordPress plugin)
No auth needed
Prerequisites: WordPress site with vulnerable Ninja Forms plugin · Access to admin-ajax.php endpoint
mistral-large-3 · analyzed May 28, 2026 Full analysis →
nomisec WORKING POC
by zycoder0day · remote
https://github.com/zycoder0day/CVE-2026-0740

This is a functional exploit for CVE-2026-0740 targeting Ninja Forms Upload, leveraging path traversal to upload arbitrary files and achieve remote code execution. The script automates nonce retrieval, file upload with traversal, and validation of the uploaded file.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ninja Forms Upload (WordPress plugin)
No auth needed
Prerequisites: WordPress site with vulnerable Ninja Forms Upload plugin · network access to target
mistral-large-3 · analyzed May 12, 2026 Full analysis →
nomisec STUB
by BastianXploited · poc
https://github.com/BastianXploited/CVE-2026-0740

The repository contains only a README.md file with minimal content (just the CVE identifier) and no exploit code or technical details. It appears to be a placeholder or stub.

Classification
Stub 100%
Attack Type
Other
Complexity
Trivial
Reliability
Theoretical
Target: unknown
No auth needed
mistral-large-3 · analyzed May 10, 2026 Full analysis →
github WORKING POC
by murrez · pythonremote
https://github.com/murrez/CVE-2026-0740

This repository contains a functional Python script that exploits a file upload vulnerability in the WordPress Ninja Forms plugin (CVE-2026-0740). The script automates the process of retrieving a nonce and uploading a malicious PHP shell to vulnerable targets listed in a file.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: WordPress Ninja Forms plugin
No auth needed
Prerequisites: list of target URLs in list.txt · Python 3 · requests library
mistral-large-3 · analyzed Apr 26, 2026 Full analysis →
nomisec WORKING POC
by 0xgh057r3c0n · remote
https://github.com/0xgh057r3c0n/CVE-2026-0740

This repository contains a functional Python exploit for CVE-2026-0740, targeting an unauthenticated arbitrary file upload vulnerability in Ninja Forms File Uploads <= 3.3.26. The exploit includes detailed logging, proxy support, and path traversal capabilities.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ninja Forms File Uploads <= 3.3.26
No auth needed
Prerequisites: Target URL · File to upload · Optional: Path traversal destination
mistral-large-3 · analyzed Apr 17, 2026 Full analysis →
nomisec WORKING POC
by whattheslime · remote
https://github.com/whattheslime/CVE-2026-0740

This repository contains a functional Python exploit for CVE-2026-0740, an unauthenticated arbitrary file upload vulnerability in Ninja Forms File Uploads <= 3.3.26. The exploit leverages a path traversal technique to upload files to arbitrary locations on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ninja Forms File Uploads <= 3.3.26
No auth needed
Prerequisites: Target URL · File to upload · Path traversal destination
mistral-large-3 · analyzed Apr 10, 2026 Full analysis →
nomisec WORKING POC
by xShadow-Here · remote
https://github.com/xShadow-Here/CVE-2026-0740

This repository contains a functional exploit for CVE-2026-0740, an unauthenticated arbitrary file upload vulnerability in Ninja Forms - File Upload plugin for WordPress. The exploit automates the process of fetching a nonce, uploading a disguised PHP shell, and renaming it to achieve remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Ninja Forms - File Upload plugin for WordPress <= 3.3.26
No auth needed
Prerequisites: WordPress site with vulnerable Ninja Forms - File Upload plugin · list.txt file containing target URLs
mistral-large-3 · analyzed Apr 09, 2026 Full analysis →

Nuclei Templates (1)

Ninja Forms File Uploads <= 3.3.26 - Arbitrary File Upload
CRITICALVERIFIEDby whattheslime
Shodan: http.html:"nfpluginsettings.js?ver="
FOFA: body="nfpluginsettings.js?ver="

Scores

CVSS v3 9.8
EPSS 0.5781
EPSS Percentile 99.0%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-04-06
CWE
CWE-434
Status published
Products (1)
SaturdayDrive/Ninja Forms - File Uploads < 3.3.26
Published Apr 07, 2026
Tracked Since Apr 07, 2026