标题:WordPress plugin Ninja Forms - File Uploads 代码问题漏洞 (CVE-2026-0740) Description:WordPress和WordPress plugin都是WordPress基金会的产品。WordPress是一套使用PHP语言开发的博客平台。该平台具有在基于PHP和MySQL的服务器上架设个人博客网站的功能。WordPress plugin是一个应用插件。 WordPress plugin Ninja Forms - File Uploads 3.3.26及之前版本存在代码问题漏洞,该漏洞源于NF_FU_AJAX_Controllers_Uploads::handle_upload函数缺少文件类型验证,
Description
Ninja Forms File Uploads plugin for WordPress versions up to and including 3.3.26 is vulnerable to unauthenticated arbitrary file upload which could lead to remote code execution.