www.securityweek.com 8/18/2026, 10:51:15 AM · external

WordPress Forminator flaw (CVE-2026-15748) exposes 300k sites

WordPress Forminator flaw (CVE-2026-15748) exposes 300k sites
Developing story vulnerability 3 articles tracked
Forminator WordPress plugin arbitrary file upload flaw (CVE-2026-15748)
CyberSIXT Evidence Panel
Primary Source wordfence.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability in the Forminator Forms plugin for WordPress, tracked as CVE-2026-15748, poses risks of remote code execution (RCE) for over 300,000 websites. The vulnerability arises from insufficient file type validation during file uploads, allowing unauthenticated attackers to upload executable files. This issue affects all versions up to 1.56.1 and was patched in version 1.56.2 released on July 31, 2026. Currently, no reports of exploitation have surfaced, but the potential for full site compromise exists through exploitation of this vulnerability.

View Primary Source Via www.securityweek.com

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline