Forminator Forms WordPress Plugin Unauthenticated RCE via PHP Upload
Critical flaw in Forminator Forms WordPress plugin (600k+ installs) lets unauthenticated attackers upload malicious PHP files and achieve remote code execution.
- Vendor
- WPMU DEV
- Product
- Forminator Forms
- CVSS
- 9.8
- EPSS (exploit probability)
- N/A
- Status
- patched
- Published
CVE-2026-15748 is a critical unauthenticated remote code execution vulnerability in Forminator Forms, a widely-deployed WordPress plugin with more than 600,000 active installations. The flaw allows an unauthenticated attacker to upload a malicious PHP file through the plugin’s file upload handling and execute arbitrary code on the server.
Severity: CVSS 9.8 (Critical). No authentication, no prior foothold required.
Affected: Forminator Forms plugin for WordPress. Check the NVD entry for the specific version range.
Action: Update Forminator Forms to the latest available version immediately via your WordPress plugin manager. If an update is not yet available in your dashboard, deactivate the plugin until a patched release can be applied.
See the 0dayNews coverage for full context and patch prioritization.
