CVE-2026-81773
largeUnauthenticated XSS in Ninja Forms File Uploads Extension for WordPress
CVE-2026-81773 is an unauthenticated cross-site scripting (XSS, CWE-79) flaw in the File Uploads extension for the Ninja Forms WordPress plugin, affecting all versions up to and including 3.3.26. Because the flaw requires no privileges or authentication (AV:N/PR:N), an unauthenticated attacker can trigger it over the web, though the CVSS vector indicates a victim, such as a site administrator, must view or interact with the attacker-supplied content for the script to execute (UI:R, S:C). If successful, the injected script runs in the victim's browser in the context of the affected site, potentially enabling session/cookie theft, unauthorized administrative actions, redirects, or malicious content injection. Any WordPress site running Ninja Forms with the File Uploads extension at version 3.3.26 or older is affected, while sites running the core Ninja Forms plugin without this extension are not implicated by this advisory. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.2% probability of exploitation within 30 days.
What to do: Update the Ninja Forms File Uploads extension to the latest available release (any version newer than 3.3.26) as soon as possible. Until patched, consider temporarily deactivating the extension or limiting file-upload forms to trusted users, and review site users and content for signs of injected scripts or unexpected administrator accounts. Current exploitation risk is assessed as low (EPSS 0.2%, no known PoC), but because the flaw is exploitable without authentication, patching should not be deferred.
| Ninja Forms File Uploads Extension (WordPress plugin) | <= 3.3.26 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-79
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L
In the news0 stories
No ingested article mentions this CVE yet.