peter bassill · operator
$ cve CVE-2022-0888 JSON

CVE-2022-0888

9.8
CRITICAL · CVSS 3.1 · EPSS 39.4% (pctl 99)

Patch early

EPSS 39.4% — above the 10% action threshold.

Description

The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS39.39% — more likely to be exploited than 99% of all CVEs
WeaknessCWE-434
On CISA KEVno
Public exploitnone known
Published2022-03-23
Last modified2026-06-17

Affected (1)

VendorProduct
ninjaformsninja forms file uploads

References

→ the Explorer  ·  watch your stack  ·  NVD