CVE-2022-0888: Ninja Forms - File Uploads Extension <= 3.3.0 - Arbitrary File Upload
The Ninja Forms - File Uploads Extension WordPress plugin is vulnerable to arbitrary file uploads due to insufficient input file type validation found in the ~/includes/ajax/controllers/uploads.php file which can be bypassed making it possible for unauthenticated attackers to upload malicious files that can be used to obtain remote code execution, in versions up to and including 3.3.0
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this Ninja Forms - File Uploads Extension WordPress plugin vulnerability?
The vulnerability ID of this vulnerability is CVE-2022-0888.
What is the severity of CVE-2022-0888 vulnerability?
The severity of CVE-2022-0888 vulnerability is critical with a score of 9.8.
How does the Ninja Forms - File Uploads Extension WordPress plugin vulnerability work?
The vulnerability in the plugin allows unauthenticated attackers to bypass input file type validation and upload malicious files.
Which version of the Ninja Forms - File Uploads Extension WordPress plugin is affected by this vulnerability?
The vulnerability affects version up to and including 3.3.0 of the Ninja Forms - File Uploads Extension WordPress plugin.
How can I fix the CVE-2022-0888 vulnerability in the Ninja Forms - File Uploads Extension WordPress plugin?
To fix the vulnerability, update the Ninja Forms - File Uploads Extension WordPress plugin to a version later than 3.3.0.