<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Ninja Forms - File Uploads (&lt;= 3.3.34) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/ninja-forms---file-uploads--3.3.34/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 02 Oct 2026 06:23:15 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/ninja-forms---file-uploads--3.3.34/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary File Operations Vulnerability in Ninja Forms File Uploads</title><link>https://feed.craftedsignal.io/briefs/2026-10-ninja-forms-vulnerability/</link><pubDate>Fri, 02 Oct 2026 06:23:15 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-ninja-forms-vulnerability/</guid><description>The Ninja Forms File Uploads plugin for WordPress contains an unauthenticated vulnerability in the Amazon S3 upload flow that allows arbitrary file read, write, and deletion via insufficient path validation.</description><content:encoded><![CDATA[<p>The Ninja Forms - File Uploads plugin for WordPress, in all versions up to and including 3.3.34, is susceptible to arbitrary file operations due to improper validation of user-supplied paths within the Amazon S3 external upload flow. An unauthenticated attacker can manipulate the file_path parameter during form submission, which the plugin subsequently utilizes for file attachments, data storage, and scheduled deletions without adequate sanitization. This vulnerability presents significant risk, as it allows attackers to read sensitive configuration files, overwrite existing files, or delete critical system data. If the server is configured to permit remote file storage, the write primitive can be leveraged to achieve remote code execution. Defenders must prioritize patching the plugin to version 3.3.35 or later and verify configurations for External File Upload actions.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows unauthenticated attackers to gain unauthorized access to server files, compromise system integrity through arbitrary writes, or cause denial-of-service by deleting critical files. The vulnerability specifically affects WordPress installations utilizing the Ninja Forms File Uploads plugin with the Amazon S3 integration enabled. If combined with email notification attachments, the impact includes unauthorized data exfiltration, while the write primitive facilitates RCE, potentially resulting in full site compromise.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the Ninja Forms File Uploads plugin to version 3.3.35 or later immediately.</li>
<li>Audit WordPress media and plugin configuration files to identify forms currently using the Amazon S3 External File Upload action.</li>
<li>Monitor web server logs for suspicious POST requests to WordPress form endpoints that contain path traversal characters (../) within parameters related to file uploads or storage paths.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application</category><category>wordpress</category><category>arbitrary-file-read</category><category>arbitrary-file-write</category><category>rce</category></item></channel></rss>