#4
The Hacker News
general
August 17, 2026 at 18:22 UTC
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
By [email protected] (The Hacker News)
AI Summary
CVE-2026-15748 (CVSS 9.8) is a critical unauthenticated remote code execution vulnerability in the Forminator Forms WordPress plugin, which has over 600,000 active installations. Exploitation is possible via malicious PHP file uploads, making this a mass-exploitation risk for the large number of WordPress sites running the plugin.
Relevance score: 83.0/100
Sponsored
Protect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected →