50,000 WordPress Sites affected by Arbitrary File Upload Vulnerability in Ninja Forms – File Upload WordPress Plugin
On January 8th, 2026, we received a submission for an Arbitrary File Upload vulnerability in Ninja Forms - File Upload, a WordPress plugin with an estimated 50,000 active installations. This vulnerability makes it possible for an unauthenticated attacker to upload arbitrary files to a vulnerable sit
ORIGINAL SOURCE →via Wordfence
ADVERTISEMENT
⚡ STAY AHEAD
Events like this, convergence-verified across 689 sources, land in your inbox every Sunday. Free.
GET THE SUNDAY BRIEFING →RELATED · cyber
- [CYBER] 🔒 pear: Kinsmen TeleMiracle
- [CYBER] Valve VRAM hack may improve gaming on 4GB GPUs — testing showed mixed results in select titles, with FPS almost tripling in certain games
- [CYBER] Mythos and friends could be a 'net positive' for UK cyber security defenses but only if they're secured, says top cyber official
- [CYBER] Microsoft warns of fake IT worker identities infiltrating cloud environments
- [CYBER] Phishing reclaims the top initial access spot, attackers experiment with AI tools
- [CYBER] The AI era demands a different kind of CISO