Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Summary
A critical security flaw in the Forminator Forms WordPress plugin, with over 600,000 active installations, allows for unauthenticated arbitrary code execution through malicious PHP uploads. The vulnerability, tracked as CVE-2026-15748, has a high CVSS score of 9.8.
IFF Assessment
FOE
This vulnerability allows attackers to execute arbitrary code on vulnerable websites, posing a significant threat to defenders.
Severity
9.8
Critical
Defender Context
This critical RCE vulnerability in a widely used WordPress plugin, Forminator Forms, requires immediate attention from defenders. They should prioritize patching or disabling the plugin to prevent exploitation, as unauthenticated attackers can gain full control of their websites.