securityonline.info 8/18/2026, 3:02:00 AM · external

CVE-2026-15748 (CVSS 9.8): Forminator Flaw Enables Pre-Auth RCE

CVE-2026-15748 (CVSS 9.8): Forminator Flaw Enables Pre-Auth RCE
Developing story vulnerability 2 articles tracked
Critical Forminator Forms plugin flaw (CVE-2026-15748) allows unauthenticated RCE
CyberSIXT Evidence Panel
Primary Source wordfence.com
CISA KEV Not in KEV
Patch Patch Status Unknown

A critical vulnerability, CVE-2026-15748, affects the Forminator Forms plugin for WordPress, risking over 600,000 sites. Scoring a CVSS of 9.8, it allows unauthenticated attackers to upload PHP files, enabling pre-auth remote code execution and potential site takeovers. Exploitation leverages flaws in the plugin's upload path, specifically targeting forms with both file upload and select fields. Affected versions include all up to 1.56.1; users are urged to update to 1.56.2 immediately and review their upload settings and directory protections.

View Primary Source Via securityonline.info

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline