A critical vulnerability, CVE-2026-15748, affects the Forminator Forms plugin for WordPress, risking over 600,000 sites. Scoring a CVSS of 9.8, it allows unauthenticated attackers to upload PHP files, enabling pre-auth remote code execution and potential site takeovers. Exploitation leverages flaws in the plugin's upload path, specifically targeting forms with both file upload and select fields. Affected versions include all up to 1.56.1; users are urged to update to 1.56.2 immediately and review their upload settings and directory protections.
CVE-2026-15748 (CVSS 9.8): Forminator Flaw Enables Pre-Auth RCE
CyberSIXT Evidence Panel
Article by CyberSIXT
Timeline Coverage
Swipe to explore timeline
-
CVE-2026-15748 (CVSS 9.8): Forminator Flaw Enables Pre-Auth RCE
securityonline.info
-
Forminator WordPress flaw lets hackers run code via file upload
cybersixt.com