A critical bug in the Forminator Forms WordPress plugin could let attackers take over vulnerable websites, potentially affecting about 300,000 sites. Tracked as CVE-2026-15748, the flaw affects Forminator versions through 1.56.1 and was patched in 1.56.2 on July 31. It allows unauthenticated arbitrary file upload through the plugin's public submission handler, which can lead to remote code execution if a site uses a custom file upload storage root where PHP execution is not blocked.
Why it matters: Website owners using Forminator should update immediately to 1.56.2 or later and review whether custom upload storage is enabled, because a successful attack can lead to full site compromise through webshells. Even without confirmed in-the-wild exploitation yet, the bug is simple enough and severe enough to treat as urgent.
Ionut Arghire
2026.08.18
100% relevant
This article establishes a distinct vulnerability and patch event centered on CVE-2026-15748 in the Forminator Forms plugin, including affected versions, exploitation conditions, and estimated exposure.
← Back to all stories