Skip to content
feed: live
>_0dayNews
CVE Record
[ CRITICAL ]CVE-2026-15748

Forminator Forms WordPress Plugin Unauthenticated RCE via PHP Upload

Critical flaw in Forminator Forms WordPress plugin (600k+ installs) lets unauthenticated attackers upload malicious PHP files and achieve remote code execution.

cat cve-2026-15748.json
Vendor
WPMU DEV
Product
Forminator Forms
CVSS
9.8
EPSS (exploit probability)
N/A
Status
patched
Published

CVE-2026-15748 is a critical unauthenticated remote code execution vulnerability in Forminator Forms, a widely-deployed WordPress plugin with more than 600,000 active installations. The flaw allows an unauthenticated attacker to upload a malicious PHP file through the plugin’s file upload handling and execute arbitrary code on the server.

Severity: CVSS 9.8 (Critical). No authentication, no prior foothold required.

Affected: Forminator Forms plugin for WordPress. Check the NVD entry for the specific version range.

Action: Update Forminator Forms to the latest available version immediately via your WordPress plugin manager. If an update is not yet available in your dashboard, deactivate the plugin until a patched release can be applied.

See the 0dayNews coverage for full context and patch prioritization.