{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/ninja-forms---file-uploads--3.3.34/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:ninja_forms:file_uploads:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.1,"id":"CVE-2026-92820"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Ninja Forms - File Uploads (\u003c= 3.3.34)"],"_cs_severities":["high"],"_cs_tags":["web-application","wordpress","arbitrary-file-read","arbitrary-file-write","rce"],"_cs_type":"advisory","_cs_vendors":["Ninja Forms"],"content_html":"\u003cp\u003eThe Ninja Forms - File Uploads plugin for WordPress, in all versions up to and including 3.3.34, is susceptible to arbitrary file operations due to improper validation of user-supplied paths within the Amazon S3 external upload flow. An unauthenticated attacker can manipulate the file_path parameter during form submission, which the plugin subsequently utilizes for file attachments, data storage, and scheduled deletions without adequate sanitization. This vulnerability presents significant risk, as it allows attackers to read sensitive configuration files, overwrite existing files, or delete critical system data. If the server is configured to permit remote file storage, the write primitive can be leveraged to achieve remote code execution. Defenders must prioritize patching the plugin to version 3.3.35 or later and verify configurations for External File Upload actions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain unauthorized access to server files, compromise system integrity through arbitrary writes, or cause denial-of-service by deleting critical files. The vulnerability specifically affects WordPress installations utilizing the Ninja Forms File Uploads plugin with the Amazon S3 integration enabled. If combined with email notification attachments, the impact includes unauthorized data exfiltration, while the write primitive facilitates RCE, potentially resulting in full site compromise.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the Ninja Forms File Uploads plugin to version 3.3.35 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit WordPress media and plugin configuration files to identify forms currently using the Amazon S3 External File Upload action.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for suspicious POST requests to WordPress form endpoints that contain path traversal characters (../) within parameters related to file uploads or storage paths.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-02T06:23:15Z","date_published":"2026-10-02T06:23:15Z","id":"https://feed.craftedsignal.io/briefs/2026-10-ninja-forms-vulnerability/","summary":"The Ninja Forms File Uploads plugin for WordPress contains an unauthenticated vulnerability in the Amazon S3 upload flow that allows arbitrary file read, write, and deletion via insufficient path validation.","title":"Arbitrary File Operations Vulnerability in Ninja Forms File Uploads","url":"https://feed.craftedsignal.io/briefs/2026-10-ninja-forms-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Ninja Forms - File Uploads (\u003c= 3.3.34)","version":"https://jsonfeed.org/version/1.1"}