A critical flaw in the Forminator Forms WordPress plugin, tracked as CVE-2026-15748, can let unauthenticated attackers upload executable files and achieve remote code execution. Defiant says the issue affects more than 300,000 websites running vulnerable versions, though there are no reports of active exploitation yet. #ForminatorForms #CVE-2026-15748 #Defiant
Keypoints
- CVE-2026-15748 is a critical arbitrary file upload vulnerability in Forminator Forms.
- The flaw is caused by insufficient file type validation in the handle_file_upload function.
- Attackers can forge form records and bypass the pluginβs dangerous file blocklist.
- Custom File Upload Storage configurations may allow uploaded PHP files to execute directly.
- Version 1.56.2 fixes the issue, but many sites may still be exposed.