Junglewise Threat Intelligence

CVE-2026-57784: Ninja Forms File Uploads Extension CSRF

CVE-2026-57784 · Severity: critical · CVSS 9.6 · Published 2026-07-23

Vendors: Ninja Forms.

Executive brief

A vulnerability exists in the File Uploads extension for Ninja Forms, a popular WordPress form builder. This flaw allows an attacker to trick an administrator or other authorized user into performing unintended actions on the website, such as changing settings or deleting data, simply by getting them to click a malicious link. If successful, this could lead to a full takeover of the website or significant data loss.

Technical details

A Cross-Site Request Forgery (CSRF) vulnerability exists in the Ninja Forms File Uploads Extension plugin for WordPress (versions <= 3.3.26). The issue stems from a lack of proper nonce validation or equivalent CSRF protections within the plugin's administrative or file-handling functions. An unauthenticated remote attacker can exploit this by crafting a malicious request and tricking a logged-in administrator into executing it via social engineering (e.g., a phishing link). Successful exploitation can lead to unauthorized configuration changes, file manipulation, or full site compromise due to the 'Changed Scope' (S:C) and high impact on confidentiality, integrity, and availability. As of the advisory date, no official patch has been confirmed.

Affected products

  • Ninja Forms Ninja Forms File Uploads Extension <= 3.3.26

Timeline

  • 2026-03-09: other: Vulnerability reported by researcher Marc-André Beaulieu
  • 2026-04-08: advisory: Initial advisory published by Patchstack
  • 2026-07-23: disclosed: CVE-2026-57784 published to the NVD dataset

References