300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

Summary

A critical arbitrary file upload vulnerability, tracked as CVE-2026-15748, has been discovered in a popular WordPress form plugin, potentially affecting up to 300,000 websites. The flaw allows unauthenticated attackers to upload and execute malicious files on vulnerable servers.

IFF Assessment

FOE

The vulnerability allows unauthenticated attackers to upload executable files, posing a direct threat to website security and data.

Severity

9.8 Critical

Defender Context

This vulnerability highlights the ongoing risk associated with popular WordPress plugins and the importance of prompt patching. Defenders should prioritize scanning their WordPress sites for this specific vulnerability and ensure the affected form plugin is updated to the latest secure version. Regular plugin audits and a robust patch management strategy are crucial to mitigate such risks.

Read Full Story →