Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Vulnerabilities

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files.

WordPress vulnerability exploited

A critical vulnerability in the Forminator Forms plugin for WordPress potentially exposes thousands of websites to remote code execution (RCE), WordPress security firm Defiant warns.

Tracked as CVE-2026-15748 (CVSS score of 9.8), the bug is described as an arbitrary file upload via the handle_file_upload function of the popular form builder plugin.

Insufficient file type validation in the affected function allows unauthenticated attackers to upload executable files, leading to code execution.

According to Defiant, the issue is a combination of several weaknesses that enable attackers to forge records using the Select field on a form, take control of the field configuration passed to the upload function, and bypass the plugin’s blocklist of dangerous file types.

“This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value,” Defiant explains.

In default configurations, files land in a protected directory that prevents PHP execution. However, if a Custom File Upload Storage root has been configured, the protection is not applied to it, and the attacker-supplied PHP code is executed when the uploaded file is requested directly.

Advertisement. Scroll to continue reading.

“As with all arbitrary file upload vulnerabilities, this can lead to complete site compromise through the use of webshells and other techniques,” Defiant notes.

The vulnerability impacts all Forminator Forms versions up to 1.56.1 and was patched in version 1.56.2, released on July 31.

The plugin has over 600,000 installations and, based on WordPress data, half of them run a vulnerable version. This means that over 300,000 websites are potentially exposed to attacks. Currently, there are no reports of the bug’s in-the-wild exploitation.

Related: GitLab Patches Critical Code Injection Vulnerability

Related: Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates

Related: Recent macOS Screen Sharing Vulnerability Exploited in Attacks

Related: Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore if detection-first security operations can keep pace with AI, or if it’s time to rethink prevention as the strongest default.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Dali Rajic is joining OpenAI as Chief Revenue Officer.

Erika Dean has been appointed Chief Information Security Officer at Tricentis.

C1 has named Jeff St. Clair Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.