A critical vulnerability in the Forminator Forms plugin for WordPress, tracked as CVE-2026-15748, poses risks of remote code execution (RCE) for over 300,000 websites. The vulnerability arises from insufficient file type validation during file uploads, allowing unauthenticated attackers to upload executable files. This issue affects all versions up to 1.56.1 and was patched in version 1.56.2 released on July 31, 2026. Currently, no reports of exploitation have surfaced, but the potential for full site compromise exists through exploitation of this vulnerability.
WordPress Forminator flaw (CVE-2026-15748) exposes 300k sites
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
WordPress Forminator flaw (CVE-2026-15748) exposes 300k sites
www.securityweek.com
-
CVE-2026-15748 (CVSS 9.8): Forminator Flaw Enables Pre-Auth RCE
cybersixt.com
-
Forminator WordPress flaw lets hackers run code via file upload
cybersixt.com