A critical flaw in Forminator Forms (CVE-2026-15748) can let unauthenticated attackers upload arbitrary files and potentially execute PHP code, leading to full site compromise on vulnerable WordPress sites. Wordfence also disclosed an authentication bypass in User Profile Builder (CVE-2026-15826) that can let attackers log in as user ID 1 and take over affected sites if automatic login is enabled. #ForminatorForms #CVE-2026-15748 #UserProfileBuilder #CVE-2026-15826 #Wordfence
Keypoints
- Forminator Forms has a critical arbitrary file upload vulnerability.
- The flaw affects over 600,000 active WordPress installations.
- Attackers can upload PHP files and achieve remote code execution.
- User Profile Builder contains an authentication bypass affecting user ID 1.
- Site owners should update to the patched versions immediately.
Read More: https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html