< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-08-17T23:52:09+05:30

Critical Unauthenticated RCE Vulnerability in Forminator WordPress Plugin via Malicious PHP Uploads

A critical unauthenticated remote code execution (RCE) vulnerability (CVE-2026-15748) exists in Forminator WordPress plugin versions prior to 1.56.2, allowing malicious PHP uploads through insufficient file validation. The flaw requires specific form configurations and could lead to complete site compromise if exploited.

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites.

The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias "

Read original article

*** END OF TRANSMISSION ***