Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

Read full story on The Hacker News
Share
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
AI disclosure

Summary

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias "

Original reporting

Open original source

Related coverage

Read full article on The Hacker News

Get the AFBytes Brief

Major stories, AI-assisted analysis, and what to watch next. Free, monthly, unsubscribe anytime.