PT-2026-76767 · WordPress · Forminator
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Forminator versions prior to the patch released in response to this disclosure
Description
An unauthenticated arbitrary file upload flaw allows an attacker to upload malicious PHP files to the server, leading to Remote Code Execution (RCE), which is the ability to execute arbitrary commands on a remote machine. This issue affects over 600,000 active installations and can result in full site compromise, including the installation of backdoors or site defacement.
Recommendations
Update the Forminator plugin to the latest patched version.
As a temporary workaround, disable the plugin.
Implement a Web Application Firewall (WAF) rule to block file uploads to the Forminator endpoint from unauthenticated users.
Fix
RCE
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Forminator