MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 11 h ago, last 11 h ago, peak #11

Ninja Forms file uploads plugin hit by high-severity flaw

Original: 🟠 CVE-2026-92820 - High (8.1) The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operat

A high-severity vulnerability, CVE-2026-92820 with a score of 8.1, has been disclosed in the Ninja Forms File Uploads plugin for WordPress. All versions up to and including 3.3.34 are affected. The flaw allows arbitrary file operations through the plugin's external Amazon S3 upload flow, which trusts an attacker-supplied file path submitted via a form. WordPress site administrators using the plugin are urged to update or disable it until a patched version is available.

Why now: A newly disclosed high-severity flaw in a widely used WordPress plugin is being flagged so site owners can patch quickly.

Ninja FormsWordPressAmazon S3

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/706849