Detects the Ninja Forms File Uploads plugin for WordPress versions up to 3.3.26 where the handle_upload function validates the source file extension but not the destination filename. An unauthenticated attacker can upload a file with a safe extension (e.g., image.jpg) and override the destination filename to a PHP file, creating a webshell that enables full remote code execution. The nf_fu_get_new_nonce AJAX action issues upload nonces without authentication, confirming the upload pipeline is active.
Is your app exploitable through CVE-2026-0740?
Scan your domain free