PT-2026-76767 · WordPress · Forminator

·

CVE-2026-15748

·

Published

2026-08-17

·

Updated

2026-08-19

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Forminator versions prior to the patch released in response to this disclosure
Description An unauthenticated arbitrary file upload flaw allows an attacker to upload malicious PHP files to the server, leading to Remote Code Execution (RCE), which is the ability to execute arbitrary commands on a remote machine. This issue affects over 600,000 active installations and can result in full site compromise, including the installation of backdoors or site defacement.
Recommendations Update the Forminator plugin to the latest patched version. As a temporary workaround, disable the plugin. Implement a Web Application Firewall (WAF) rule to block file uploads to the Forminator endpoint from unauthenticated users.

Fix

RCE

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15748

Affected Products

Forminator