CRITICAL
Ninja Forms - File Uploads Extension <= 3.3.0 - Arbitrary File Upload
Published Mar 23, 2022
9.8
CRITICALCVSS 3.1
EPSS 39.39%
Description
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0
Affected products
-
- Version 0StatusaffectedConstraints<=3.3.0
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| SaturdayDrive | Ninja Forms - File Uploads | unaffected |
|
- ≤ 3.3.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (3)
- https://gist.github.com/Xib3rR4dAr/5f0accbbfdee279c68ed144da9cd8607 ExploitPatchThird Party Advisory
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f00eeaef-f277-481f-9e18-bf1ced0015a0?source=cve
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0888 Third Party Advisory
| Link | Providers | Tags |
|---|---|---|
| https://gist.github.com/Xib3rR4dAr/5f0accbbfdee279c68ed144da9cd8607 | ExploitPatchThird Party Advisory | |
| https://www.wordfence.com/threat-intel/vulnerabilities/id/f00eeaef-f277-481f-9e18-bf1ced0015a0?source=cve | ||
| https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0888 | Third Party Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Wordfence
Published Mar 23, 2022
Updated Apr 8, 2026
Reserved Mar 8, 2022
Link CVE-2022-0888
CISA Vulnrichment
Updated n/a