A critical unauthenticated arbitrary file upload flaw in the Ninja Forms – File Uploads WordPress plugin allows attackers to bypass extension validation and upload PHP webshells, enabling full remote code execution on the underlying web server.
Read more about Emerging Threat: (CVE-2026-0740) Ninja Forms File Upload Unauthenticated RCE