Arbitrary File Upload Vulnerability in Forminator Forms Plugin by WordPress
CVE-2026-15748
What is CVE-2026-15748?
The Forminator Forms plugin for WordPress is susceptible to an arbitrary file upload attack due to inadequate file type validation in the handle_file_upload function. Attackers can exploit this vulnerability by using specially crafted MIME types that bypass the system's dangerous-extension blocklist. Additionally, a public submission handler incorrectly trusts upload field configurations, which can be manipulated via a forged Select field value. As a result, unauthenticated attackers could potentially upload executable files, leading to a risk of remote code execution.
Affected Version(s)
Forminator Forms β Contact Form, Payment Form & Custom Form Builder 0 <= 1.56.1
News Articles
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Forminator CVE-2026-15748 lets unauthenticated attackers upload PHP files and reach RCE on sites using vulnerable form configurations.
14 hours ago
References
CVSS V3.1
Timeline
Vulnerability published
- π°
First article discovered by The Hacker News
Vulnerability Reserved