300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
A critical flaw in the Forminator Forms WordPress plugin, tracked as CVE-2026-15748, can let unauthenticated attackers upload executable files and achieve remote code execution. Defiant says the issue affects more than 300,000 websites running vulnerable versions, though there are no reports of active exploitation yet. #ForminatorForms #CVE-2026-15748 #Defiant

Keypoints

  • CVE-2026-15748 is a critical arbitrary file upload vulnerability in Forminator Forms.
  • The flaw is caused by insufficient file type validation in the handle_file_upload function.
  • Attackers can forge form records and bypass the plugin’s dangerous file blocklist.
  • Custom File Upload Storage configurations may allow uploaded PHP files to execute directly.
  • Version 1.56.2 fixes the issue, but many sites may still be exposed.

Read More: https://www.securityweek.com/300000-wordpress-sites-potentially-exposed-to-hacking-due-to-form-plugin-flaw/