CVE-2026-0740 | SaturdayDrive Ninja Forms Plugin up to 3.3.26 on WordPress handle_upload unrestricted upload (EUVD-2026-19572 / CNNVD-202604-1403)
A vulnerability was found in SaturdayDrive Ninja Forms Plugin up to 3.3.26 on WordPress and classified as critical. The affected element is the function NF_FU_AJAX_Controllers_Uploads::handle_upload. Executing a manipulation can lead to unrestricted upload.
This vulnerability is tracked as CVE-2026-0740. The attack can be launched remotely. No exploit exists.
It is suggested to upgrade the affected component.