Ninja Forms Plugin Zero-Day: Unauthenticated File Upload RCE (infosecurity-magazine.com)
0xBASE INTEL BRIEF
- Unauthenticated arbitrary file upload vulnerability in Ninja Forms.
- Allows remote code execution on WordPress sites.
- Update to version 3.3.27 to patch the flaw.
"A critical security vulnerability has been discovered in the Ninja Forms WordPress plugin, allowing unauthenticated attackers to upload arbitrary files and execute remote code. Users must update to version 3.3.27 immediately to mitigate the risk."
no comments yet.