Arbitrary File Upload Vulnerability in Forminator Forms Plugin by WordPress
CVE-2026-15748

9.8CRITICAL

Key Information:

Badges

πŸ“° News Worthy

What is CVE-2026-15748?

The Forminator Forms plugin for WordPress is susceptible to an arbitrary file upload attack due to inadequate file type validation in the handle_file_upload function. Attackers can exploit this vulnerability by using specially crafted MIME types that bypass the system's dangerous-extension blocklist. Additionally, a public submission handler incorrectly trusts upload field configurations, which can be manipulated via a forged Select field value. As a result, unauthenticated attackers could potentially upload executable files, leading to a risk of remote code execution.

Affected Version(s)

Forminator Forms – Contact Form, Payment Form & Custom Form Builder 0 <= 1.56.1

News Articles

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

Forminator CVE-2026-15748 lets unauthenticated attackers upload PHP files and reach RCE on sites using vulnerable form configurations.

14 hours ago

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • πŸ“°

    First article discovered by The Hacker News

  • Vulnerability Reserved

Credit

daroo
.