CVE-2022-0888
9.8
CRITICAL · CVSS 3.1 · EPSS 39.4% (pctl 99)
Patch early
EPSS 39.4% — above the 10% action threshold.
Description
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0
Scoring
| CVSS | 9.8 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 39.39% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-434 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2022-03-23 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| ninjaforms | ninja forms file uploads |
References
- https://gist.github.com/Xib3rR4dAr/5f0accbbfdee279c68ed144da9cd8607
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f00eeaef-f277-481f-9e18-bf1ced0015a0?source=cve
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0888
- https://gist.github.com/Xib3rR4dAr/5f0accbbfdee279c68ed144da9cd8607
- https://www.wordfence.com/threat-intel/vulnerabilities/id/f00eeaef-f277-481f-9e18-bf1ced0015a0?source=cve
- https://www.wordfence.com/vulnerability-advisories/#CVE-2022-0888
→ the Explorer · watch your stack · NVD