Ninja Forms - File Uploads Extension <= 3.3.0 - Arbitrary File Upload
Vulnerability Description
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-0888
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Muhammad Zeeshan
References
Affected Vendor
SaturdayDrive
View all reports →