Critical RCE Flaw Found in Popular WordPress Plugin Forminator
A severe vulnerability in the Forminator WordPress plugin could allow unauthenticated remote code execution. Over 600,000 live websites are potentially at risk.
TL;DR
- CVE-2026-15748 is a critical flaw in Forminator Forms plugin with a 9.8 CVSS score.
- It allows unauthenticated attackers to upload malicious PHP files for remote code execution.
- Over 600,000 WordPress sites using the plugin are potentially vulnerable.
- Site owners should update to the latest patched version immediately.
- Security researchers recommend scanning for unauthorized file uploads as a precaution.
A newly disclosed critical vulnerability in the Forminator Forms WordPress plugin poses a significant threat to over 600,000 active websites. Tracked as CVE-2026-15748, the flaw enables unauthenticated remote code execution through malicious PHP file uploads.
With a near-maximum CVSS score of 9.8, this vulnerability allows attackers to take full control of affected sites without needing login credentials. The issue was identified and responsibly reported by a security researcher, but organizations running the plugin must act swiftly to mitigate risks.
Vulnerability Details
- The flaw resides in how the plugin handles file uploads, allowing PHP files to be executed remotely.
- Attackers do not require authentication to exploit the vulnerability, increasing its severity.
- Once exploited, attackers can execute arbitrary code, potentially leading to full site compromise.
- CVE-2026-15748 received a CVSS score of 9.8, indicating critical risk.
Impact and Recommendations
- More than 600,000 WordPress sites currently use the vulnerable version of Forminator Forms.
- Organizations should immediately update the plugin to the latest patched version.
- Web administrators are advised to audit their servers for suspicious PHP uploads.
- Proactive monitoring for unusual activity can help detect potential exploitation attempts.
- Using a web application firewall (WAF) may provide temporary mitigation for unpatched sites.
Sources
Sources
Security email updates
One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.