Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Overview
A serious vulnerability has been found in Forminator Forms, a popular WordPress plugin with over 600,000 installations. This flaw, identified as CVE-2026-15748 and rated 9.8 out of 10 on the CVSS scale, allows attackers to execute arbitrary code on affected websites without authentication. Discovered by a security researcher, this issue poses a significant risk as it could enable malicious users to upload harmful PHP files, compromising the security of the sites. Website owners using this plugin should be particularly vigilant, as the potential for exploitation is high. Immediate action is necessary to protect their systems and data.
Key Takeaways
- Affected Systems: Forminator Forms WordPress plugin, versions prior to the patched release; WordPress websites utilizing this plugin.
- Action Required: Users should update the Forminator Forms plugin to the latest version immediately to mitigate the risk.
- Timeline: Newly disclosed
Original Article Summary
A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias "
Impact
Forminator Forms WordPress plugin, versions prior to the patched release; WordPress websites utilizing this plugin.
Exploitation Status
The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.
Timeline
Newly disclosed
Remediation
Users should update the Forminator Forms plugin to the latest version immediately to mitigate the risk. Additionally, website administrators should review their file upload settings and implement security measures to restrict unauthorized uploads.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, RCE, and 1 more.