CVE-2026-57784

WordPress Ninja Forms File Uploads Extension plugin <= 3.3.26 - Cross Site Request Forgery (CSRF) vulnerability

Unauthenticated Cross Site Request Forgery (CSRF) in Ninja Forms File Uploads Extension <= 3.3.26 versions.


We have discovered 4,387 live websites that are affected by CVE-2026-57784.

Run a Free Instant Scan




Affected Software

Product  Ninja Forms File Uploads
Category Wordpress Plugins
Vulnerable Domains4,387 live websites (40% of Ninja Forms File Uploads install base)
Vulnerable Versions
  • from 0 through 3.3.26
Vulnerable Versions Count45 versions ( 92% of all versions)


Common Weakness Enumeration

CWE-352 Cross-Site Request Forgery (CSRF)



Details

  • Published - Jul 23, 2026
  • Updated - Jul 23, 2026

Credits

  • Marc-André Beaulieu (h3dg3h0g) | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-57784
United States2,077 websites



Germany324 websites
GB276 websites
Denmark219 websites
France215 websites
Canada158 websites
Australia126 websites
Netherlands125 websites
Switzerland94 websites
Italy74 websites

Website Distribution by TLD

Number of websites using CVE-2026-57784
.com1,961 websites
.org427 websites
.de215 websites
.co.uk196 websites
.dk187 websites
.com.au133 websites
.nl116 websites
.fr109 websites
.ca98 websites
.net86 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-57784

Top websites that are affected by CVE-2026-57784. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.fr France**,***
*****.org United States**,***
****.hu Hungary**,***
***.org United States**,***
***********.com United States**,***
********.de Germany**,***
***********.de Germany**,***
***.com United States**,***
************.com United States**,***
*******.com United States**,***
See full domain list

FAQ

CVE-2026-57784 is Cross-Site Request Forgery (CSRF) in Ninja Forms File Uploads
A total of 4,387 websites have been identified as vulnerable to CVE-2026-57784, based on global website indexing conducted by WebTechSurvey.
The Ninja Forms File Uploads is affected by the CVE-2026-57784 vulnerability.
Ninja Forms File Uploads versions up to and including 3.3.26 are vulnerable to CVE-2026-57784.