{"ok":true,"trend":{"id":706849,"platform":"mastodon","region":"global","key":"🟠 cve-2026-92820 - high (8.1) the ninja forms - file uploads plugin for wordpress is vulnerable to arbitrary file operat","title":"🟠 CVE-2026-92820 - High (8.1) The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operat","url":"https://mastodon.social/@thehackerwire/117370032485120127","first_seen":"2026-10-02T07:24:05.046293Z","last_seen":"2026-10-02T07:24:05.046293Z","last_rank":11,"peak_rank":11,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.6896875,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A high-severity vulnerability, CVE-2026-92820 with a score of 8.1, has been disclosed in the Ninja Forms File Uploads plugin for WordPress. All versions up to and including 3.3.34 are affected. The flaw allows arbitrary file operations through the plugin's external Amazon S3 upload flow, which trusts an attacker-supplied file path submitted via a form. WordPress site administrators using the plugin are urged to update or disable it until a patched version is available.","why":"A newly disclosed high-severity flaw in a widely used WordPress plugin is being flagged so site owners can patch quickly.","tone":"negative","entities":["Ninja Forms","WordPress","Amazon S3"],"summarized_at":"2026-10-02T07:25:16.522308Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":959},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"Ninja Forms file uploads plugin hit by high-severity flaw","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-02T07:24:05.046293Z","rank":11,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@thehackerwire/117370032485120127","author":"thehackerwire","title":null,"snippet":"🟠 CVE-2026-92820 - High (8.1) The Ninja Forms - File Uploads plugin for WordPress is vulnerable to arbitrary file operations in all versions up to, and including, 3.3.34 via the external (Amazon S3) upload flow. The plugin trusts an attacker-supplied file path from the form…","posted_at":"2026-10-02T07:02:47.969000Z","likes":0}],"elsewhere":[],"window":"7d"}}