Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

Summary

A critical security flaw in the Forminator Forms WordPress plugin, with over 600,000 active installations, allows for unauthenticated arbitrary code execution through malicious PHP uploads. The vulnerability, tracked as CVE-2026-15748, has a high CVSS score of 9.8.

IFF Assessment

FOE

This vulnerability allows attackers to execute arbitrary code on vulnerable websites, posing a significant threat to defenders.

Severity

9.8 Critical

Defender Context

This critical RCE vulnerability in a widely used WordPress plugin, Forminator Forms, requires immediate attention from defenders. They should prioritize patching or disabling the plugin to prevent exploitation, as unauthenticated attackers can gain full control of their websites.

Read Full Story →