Interestana
Home/News/Forminator WordPress Plugin Flaw Allows Unauthenticated RCE
The Hacker News2 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Forminator WordPress Plugin Flaw Allows Unauthenticated RCE

Forminator WordPress Plugin Flaw Allows Unauthenticated RCE

A critical security vulnerability has been identified in Forminator Forms, a widely-used WordPress plugin with over 600,000 active installations. This flaw, designated as CVE-2026-15748, carries a severity rating of 9.8 out of 10.0 on the Common Vulnerability Scoring System (CVSS), indicating a critical risk. The vulnerability could be exploited by attackers to achieve arbitrary code execution (RCE) on vulnerable websites without requiring any prior authentication.

The vulnerability was discovered and reported by a security researcher operating under the online alias "". The specific technical details of the exploit involve the ability for an unauthenticated attacker to upload a malicious PHP file. This uploaded file can then be executed on the server, granting the attacker control over the affected WordPress site. The Forminator plugin is developed by WPMU DEV and is integrated into numerous WordPress websites to create custom forms for various purposes, including contact forms, surveys, and order forms. Its extensive functionality and large user base make this vulnerability a significant concern for website security.

Arbitrary code execution is a severe type of security breach where an attacker can run any command or code on a target system. In the context of a WordPress website, this could lead to a range of malicious activities, such as defacing the website, stealing sensitive user data (including login credentials and payment information), injecting malware, or using the compromised server for further attacks. The high CVSS score of 9.8 underscores the ease with which this vulnerability can be exploited and the potential impact of a successful attack. The lack of authentication requirement is particularly concerning, as it lowers the barrier to entry for potential attackers.

While the specific details of the researcher's disclosure are limited in the provided information, the nature of the vulnerability suggests a potential issue within the file upload handling mechanisms of the Forminator plugin. WordPress plugins are a common vector for security breaches due to their extensive functionality and the sheer number of active installations. Developers of plugins are continuously working to patch vulnerabilities, but the time lag between discovery and patching, coupled with the speed at which attackers can exploit known flaws, creates a persistent security challenge for website administrators. Users of the Forminator plugin are strongly advised to monitor for security updates and apply any patches released by WPMU DEV as soon as they become available to mitigate the risk of exploitation.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next