Home / Aug 18, 2026 / Story
0
#4 The Hacker News general August 17, 2026 at 18:22 UTC

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

By [email protected] (The Hacker News)

AI Summary

CVE-2026-15748 (CVSS 9.8) is a critical unauthenticated remote code execution vulnerability in the Forminator Forms WordPress plugin, which has over 600,000 active installations. Exploitation is possible via malicious PHP file uploads, making this a mass-exploitation risk for the large number of WordPress sites running the plugin.

Relevance score: 83.0/100

# More from August 18