ZeroHour

CVE-2026-81773

large

Unauthenticated XSS in Ninja Forms File Uploads Extension for WordPress

CVSS 3.1
7.1 high
EPSS
<1%p8
Published
()
Modified
AI analysis

CVE-2026-81773 is an unauthenticated cross-site scripting (XSS, CWE-79) flaw in the File Uploads extension for the Ninja Forms WordPress plugin, affecting all versions up to and including 3.3.26. Because the flaw requires no privileges or authentication (AV:N/PR:N), an unauthenticated attacker can trigger it over the web, though the CVSS vector indicates a victim, such as a site administrator, must view or interact with the attacker-supplied content for the script to execute (UI:R, S:C). If successful, the injected script runs in the victim's browser in the context of the affected site, potentially enabling session/cookie theft, unauthorized administrative actions, redirects, or malicious content injection. Any WordPress site running Ninja Forms with the File Uploads extension at version 3.3.26 or older is affected, while sites running the core Ninja Forms plugin without this extension are not implicated by this advisory. No public proof-of-concept, KEV listing, or confirmed in-the-wild exploitation is known, and EPSS estimates only a 0.2% probability of exploitation within 30 days.

What to do: Update the Ninja Forms File Uploads extension to the latest available release (any version newer than 3.3.26) as soon as possible. Until patched, consider temporarily deactivating the extension or limiting file-upload forms to trusted users, and review site users and content for signs of injected scripts or unexpected administrator accounts. Current exploitation risk is assessed as low (EPSS 0.2%, no known PoC), but because the flaw is exploitable without authentication, patching should not be deferred.

Affected
Ninja Forms File Uploads Extension (WordPress plugin)<= 3.3.26
Estimated exposure
largetens of thousands of WordPress sites (on the order of 10,000-100,000) — The affected code is a paid add-on that runs on top of the Ninja Forms plugin, which has on the order of 900,000 active WordPress installs, so only a subset of those sites that purchased and activated the File Uploads extension are…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Unauthenticated Cross Site Scripting (XSS) in Ninja Forms File Uploads Extension <= 3.3.26 versions.

Ecosystems
WordPress
Weakness
CWE-79
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:L

In the news

No ingested article mentions this CVE yet.