Sceawere
Vulnerability Detail
CVE-2026-92820UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Ninja Forms Arbitrary File Operations
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.1
- Creation Date
- 17h ago
- Vendor
- SaturdayDrive
- Product
- Ninja Forms - File Uploads
- Attack Type
- CWE-434 Unrestricted Upload of File with Dangerous Type
- Vector String
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- HIGH
Narrative and Response
Description
The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission and stores it as the upload's file_path, which is then used without validation to attach a file to the form's notification email (arbitrary file read), to write fetched content (arbitrary file write, leading to remote code execution when the external store is configured), and in a scheduled deletion (arbitrary file deletion). This makes it possible for unauthenticated attackers to read, write, or delete arbitrary files on the server. Exploitation requires the site to use the plugin's External File Upload (Amazon S3) action; the read variant additionally requires a form Email action configured to attach the uploaded file.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.1",
"pubDate": "2026-10-02T06:16:43.197Z",
"pubdate": "2026-10-02T06:16:43.197Z",
"executiveSummary": "The Ninja Forms - File Uploads plugin for WordPress, in versions up to and including 3.3.34, contains a critical vulnerability allowing unauthenticated attackers to perform arbitrary file operations. The flaw resides in the external (Amazon S3) upload flow, where user-supplied file paths are processed without adequate validation or sanitization.\nThe vulnerability encompasses arbitrary file read, write, and deletion capabilities. By manipulating the file_path parameter during the form submission process, an attacker can gain unauthorized access to sensitive server data, overwrite critical application files, or delete files, potentially leading to a full system compromise via Remote Code Execution (RCE).\nExploitation is contingent upon the site utilizing the plugin's External File Upload (Amazon S3) functionality. The read variant further requires a configured Email action that includes attachments. This vulnerability poses a severe risk to site integrity and confidentiality, as it bypasses standard authentication and access control mechanisms, allowing remote unauthenticated actors to exert significant control over the filesystem.",
"technicalDetails": "The root cause of this vulnerability is improper input validation within the Ninja Forms - File Uploads plugin's handling of Amazon S3 external upload requests. The plugin incorrectly treats the user-supplied file path provided in the form submission as a trusted source for the internal 'file_path' variable. Because the plugin fails to sanitize this input or implement path validation checks, it permits directory traversal and absolute path injection.\nThe vulnerability facilitates three distinct attack vectors based on the plugin's internal file handling logic:\n1. Arbitrary File Read: When the form is configured with an Email action set to include file attachments, the plugin uses the attacker-controlled 'file_path' to locate the file on the server. If an attacker submits a path to a sensitive file (e.g., wp-config.php), the plugin reads the contents of the target file and transmits it via email to the attacker.\n2. Arbitrary File Write/RCE: When the Amazon S3 external store is configured, the plugin uses the tainted 'file_path' to write fetched external content to the local filesystem. By providing an arbitrary path, an attacker can overwrite existing application code. In a WordPress environment, overwriting theme or plugin files with malicious payloads allows for Remote Code Execution.\n3. Arbitrary File Deletion: The plugin includes a scheduled task for deleting uploaded files. Because the path stored in the database is directly derived from user input without validation, an attacker can manipulate the deletion routine to remove critical system files, causing a Denial of Service (DoS) or creating conditions for further exploitation by removing security-related lockfiles or configuration files.\nThe attack flow proceeds as follows: An unauthenticated attacker identifies a form on the target WordPress site using the Ninja Forms File Uploads plugin with S3 integration. The attacker crafts a request containing a malicious file path. This input is stored in the database as the 'file_path' for the upload object. Depending on the desired outcome, the attacker triggers the email notification routine, the file write process, or the file cleanup service. Each of these components consumes the unvalidated 'file_path', resulting in unintended file system operations performed with the privileges of the web server process."
}