Forminator WordPress Plugin RCE Flaw Hits 600K Sites
CVE-2026-15748 (CVSS 9.8) in Forminator Forms lets unauthenticated attackers upload PHP files and achieve remote code execution. Update immediately.

A critical remote code execution vulnerability in Forminator Forms — a WordPress plugin installed on more than 600,000 sites — has been publicly disclosed. CVE-2026-15748 carries a CVSS score of 9.8 and requires no authentication to exploit. The attack vector is the plugin’s file upload functionality: a malicious PHP file can be uploaded and subsequently executed on the server.
If you run Forminator Forms, update it now before finishing this paragraph.
What’s vulnerable
Forminator Forms is a full-featured drag-and-drop form builder maintained by WPMU DEV, commonly used for contact forms, quizzes, surveys, and payment forms. Its file upload handling, exposed to unauthenticated visitors in affected versions, fails to adequately restrict uploaded file types. An attacker who can reach the upload endpoint can submit a PHP file and then trigger its execution — resulting in arbitrary server-side code execution with the privileges of the web server process.
CVSS 9.8 is accurate: the combination of no-auth access and direct RCE puts this at the top of the risk stack for any site running the vulnerable version. The disclosure was reported by The Hacker News on August 17, 2026.
No confirmed exploitation in the wild has been reported at the time of writing, but a CVSS 9.8 file-upload RCE in a plugin with 600,000+ installs will attract attention quickly. The window between “public disclosure” and “active mass scanning” for vulnerabilities like this is typically measured in hours, not days.
What to do
Update immediately. Go to your WordPress admin → Plugins → Installed Plugins. If Forminator Forms shows an available update, apply it now.
If your plugin manager does not yet show an update:
- Deactivate the plugin until a patched release is available. A deactivated plugin’s upload endpoints go offline.
- Check the official Forminator changelog directly to track when a fix is released.
- Consider whether any form submissions that include file uploads could have been abused since the disclosure date.
For managed WordPress and agency operators: check all client sites for the plugin. Forminator is popular with agencies because of its feature set — it’s easy to install once and forget.
Patch priority call
This is your top WordPress remediation task this week. It joins a pattern of critical plugin flaws: a CVSS 9.8 authentication bypass in User Session Synchronizer and 6Storage Rentals, an RCE via Imagick in WordPress 7.0.4, and a supply-chain attack on BdThemes that planted rogue admin accounts. The plugin ecosystem remains a high-velocity attack surface.
The full CVE record: CVE-2026-15748.
- [ CRITICAL ]CVE-2026-15748Forminator Forms WordPress Plugin Unauthenticated RCE via PHP Upload
Found this useful? Share it.


