Mmastodon TechnologyCybersecurity first seen 4 h ago, last 4 h ago, peak #11
Ninja Forms file uploads plugin hit by high-severity flaw
Original: 🟠 CVE-2026-92820 - High (8.1) The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operat
A high-severity vulnerability, CVE-2026-92820 with a score of 8.1, has been disclosed in the Ninja Forms File Uploads plugin for WordPress. All versions up to and including 3.3.34 are affected. The flaw allows arbitrary file operations through the plugin's external Amazon S3 upload flow, which trusts an attacker-supplied file path submitted via a form. WordPress site administrators using the plugin are urged to update or disable it until a patched version is available.
Why now: A newly disclosed high-severity flaw in a widely used WordPress plugin is being flagged so site owners can patch quickly.
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/706849