CVE-2026-15748: Critical Forminator WordPress Flaw Enables Unauthenticated RCE
ID: 67c1b630-212d-5903-ba65-6778b381b4fd
STIX ID: report--67c1b630-212d-5903-ba65-6778b381b4fd
Feed Name: SOC Prime Blog
A critical arbitrary file upload vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin (versions up to and including 1.56.1) allows unauthenticated attackers—by abusing a combination of a Select field and a File Upload field—to bypass file-type filtering and upload executable PHP files; on sites using custom upload storage without proper .htaccess protection this can result in remote code execution. Administrators should upgrade to Forminator 1.56.2, inspect upload storage and forms for the vulnerable configuration, and hunt for suspicious uploads or web-shell activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
