URL has been copied successfully!
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
URL has been copied successfully!

Collecting Cyber-News from over 60 sources

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites.The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias “

First seen on thehackernews.com

Jump to article: thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html

Loading

Share via Email
Share on Facebook
Tweet on X (Twitter)
Share on Whatsapp
Share on LinkedIn
Share on Xing
Copy link