Skip to content
Threat Feed
high advisory

Arbitrary File Operations Vulnerability in Ninja Forms File Uploads

The Ninja Forms File Uploads plugin for WordPress contains an unauthenticated vulnerability in the Amazon S3 upload flow that allows arbitrary file read, write, and deletion via insufficient path validation.

CVE search metadata

CVE search record: CVE-2026-92820. Severity: high. CVSS: 8.1. KEV: no. Product: Ninja Forms - File Uploads (<= 3.3.34). Brief: Arbitrary File Operations Vulnerability in Ninja Forms File Uploads. Brief link: https://feed.craftedsignal.io/briefs/2026-10-ninja-forms-vulnerability/

The Ninja Forms - File Uploads plugin for WordPress, in all versions up to and including 3.3.34, is susceptible to arbitrary file operations due to improper validation of user-supplied paths within the Amazon S3 external upload flow. An unauthenticated attacker can manipulate the file_path parameter during form submission, which the plugin subsequently utilizes for file attachments, data storage, and scheduled deletions without adequate sanitization. This vulnerability presents significant risk, as it allows attackers to read sensitive configuration files, overwrite existing files, or delete critical system data. If the server is configured to permit remote file storage, the write primitive can be leveraged to achieve remote code execution. Defenders must prioritize patching the plugin to version 3.3.35 or later and verify configurations for External File Upload actions.

Impact

Successful exploitation allows unauthenticated attackers to gain unauthorized access to server files, compromise system integrity through arbitrary writes, or cause denial-of-service by deleting critical files. The vulnerability specifically affects WordPress installations utilizing the Ninja Forms File Uploads plugin with the Amazon S3 integration enabled. If combined with email notification attachments, the impact includes unauthorized data exfiltration, while the write primitive facilitates RCE, potentially resulting in full site compromise.

Recommendation

  • Upgrade the Ninja Forms File Uploads plugin to version 3.3.35 or later immediately.
  • Audit WordPress media and plugin configuration files to identify forms currently using the Amazon S3 External File Upload action.
  • Monitor web server logs for suspicious POST requests to WordPress form endpoints that contain path traversal characters (../) within parameters related to file uploads or storage paths.

Immediate actions

Upgrade Ninja Forms - File Uploads plugin to 3.3.35 or later

IT Operations 24h

Mitigations

Upgrade to version 3.3.35

immediate IT Operations

CVE-2026-92820