Published Monday, August 17, 2026 at 04:30 PM PT

BLUF: The Hacker News reports a flaw in the Forminator WordPress plugin that permits unauthenticated attackers to achieve remote code execution through malicious PHP file uploads. Patch status, affected versions, and active exploitation remain unconfirmed; monitoring ongoing.
DETAILS
- Vulnerability type: Remote Code Execution via unauthenticated PHP upload in Forminator plugin
- Attack vector: Malicious PHP file upload (likely bypassing upload restrictions or file-type validation)
- Authentication required: None — attackers do not need valid WordPress credentials
- Source: The Hacker News reporting; full CVE details and PoC availability unconfirmed
- Temporal status: No disclosure date, patch timeline, or active exploitation confirmation available
IMPACT
- Affected software: Forminator WordPress plugin (specific versions unknown)
- Scope: Any WordPress installation running vulnerable Forminator plugin
- Severity: Critical — unauthenticated RCE execution permits full server compromise, data theft, malware deployment, and lateral movement
- Context: Forminator is a form-building plugin with unknown download/install prevalence; impact scope cannot be estimated without version/deployment data
RECOMMENDED ACTIONS
Immediate (pending clarification):
- Inventory: Identify WordPress instances using Forminator plugin and current version
- Monitor: Watch Forminator’s official repository, WordPress.org plugin page, and security advisories (CVE/NVD) for patch announcements and exploit details
- Suspend if critical: If active exploitation is confirmed, consider disabling Forminator until patch is available and tested
- Prepare patches: Track the official Forminator fix and test in non-production before rolling out
Do NOT:
- Apply unverified patches from third-party sources
- Expose WordPress admin credentials pending clarification
SOURCES
- The Hacker News (title reference; full advisory URL unavailable)
- ALERT STATUS: Unconfirmed — awaiting CVE publication, version specifics, and exploitation data
- Related context: Prior WordPress RCE vulnerabilities (wp2shell, WordPress Core flaws) indicate elevated WordPress plugin risk; cross-check Forminator’s patch history for similar bypasses
Next update when: CVE published or active exploitation confirmed.
Recent high-severity events at publish time:

