← Back to blog

Critical RCE Flaw Found in Popular WordPress Plugin Forminator

A severe vulnerability in the Forminator WordPress plugin could allow unauthenticated remote code execution. Over 600,000 live websites are potentially at risk.

TL;DR

  • CVE-2026-15748 is a critical flaw in Forminator Forms plugin with a 9.8 CVSS score.
  • It allows unauthenticated attackers to upload malicious PHP files for remote code execution.
  • Over 600,000 WordPress sites using the plugin are potentially vulnerable.
  • Site owners should update to the latest patched version immediately.
  • Security researchers recommend scanning for unauthorized file uploads as a precaution.

A newly disclosed critical vulnerability in the Forminator Forms WordPress plugin poses a significant threat to over 600,000 active websites. Tracked as CVE-2026-15748, the flaw enables unauthenticated remote code execution through malicious PHP file uploads.

With a near-maximum CVSS score of 9.8, this vulnerability allows attackers to take full control of affected sites without needing login credentials. The issue was identified and responsibly reported by a security researcher, but organizations running the plugin must act swiftly to mitigate risks.

Vulnerability Details

  • The flaw resides in how the plugin handles file uploads, allowing PHP files to be executed remotely.
  • Attackers do not require authentication to exploit the vulnerability, increasing its severity.
  • Once exploited, attackers can execute arbitrary code, potentially leading to full site compromise.
  • CVE-2026-15748 received a CVSS score of 9.8, indicating critical risk.

Impact and Recommendations

  • More than 600,000 WordPress sites currently use the vulnerable version of Forminator Forms.
  • Organizations should immediately update the plugin to the latest patched version.
  • Web administrators are advised to audit their servers for suspicious PHP uploads.
  • Proactive monitoring for unusual activity can help detect potential exploitation attempts.
  • Using a web application firewall (WAF) may provide temporary mitigation for unpatched sites.

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.