CVE-2026-92820

CVE-2026-92820 published: The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form submission a...

View full NVD advisory → ← Back to CVE watch