Skip to main content
Back to Newswire
Security

Critical Forminator flaw exposes vulnerable WordPress sites to code execution

Critical Forminator flaw exposes vulnerable WordPress sites to code execution Image: Primary
A disclosed flaw in the Forminator Forms WordPress plugin can allow unauthenticated attackers to upload executable PHP files and potentially take over susceptible sites. Wordfence rates CVE-2026-15748 at CVSS 9.8 and says it affects versions through 1.56.1; version 1.56.2, released July 31, addresses it. Exploitation requires a form with both File Upload and Select fields. Default upload storage may block PHP execution, but custom storage roots may lack that safeguard.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire