Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites.

The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias “

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

Launch HN: Bloomy (YC S26) – AI-powered mastery learning for K-12

Launch HN: Bloomy (YC S26) – AI-powered mastery learning for K-12 Source: Hacker News

Attack Update: Top 5 Attack-IPs auf doode.info – 03.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 466 requests (recent log) 216.244.66.232 — 134 requests (recent log) 34.182.88.105 — 108 requests (recent

Attack Update: Top 5 Attack-IPs auf doode.info – 16.08.2026

Watchtower Attack Update. Hier die aktuellen Top 5 Attack-IPs, die auf doode.info klopfen. 89.167.35.212 — 193 requests (recent log) 34.48.32.149 — 151 requests (recent log) 51.15.217.215 — 122 requests (recent