
🛡️ CVE-2026-15748: Forminator WordPress Plugin Unauthenticated RCE—Arbitrary File Upload Flaw
Published Wednesday, August 19, 2026 at 10:38 AM PT BLUF: Critical vulnerability in Forminator WordPress plugin (CVSS 9.8) allows unauthenticated attackers to upload and execute arbitrary PHP files, resulting in complete website takeover. Patch status unknown. Immediate defensive action required for all WordPress installations running Forminator. DETAILS Vulnerability: Arbitrary file upload flaw in Forminator Forms plugin for WordPress. Requires no authentication to exploit. CVSS Score: 9.8 (Critical). Combines high confidentiality, integrity, and availability impact with network-accessible attack vector. Attack Surface: Authenticated requirement not present—any unauthenticated user can trigger exploitation, including automated scanners. Payload: Uploaded executable PHP files can be executed server-side, granting attackers command execution under the web server process context. Affected Product: Forminator plugin for WordPress. Specific affected versions not confirmed in available intel; version cap unknown. IMPACT Scope: All WordPress sites with Forminator plugin installed and active are potentially vulnerable. Blast Radius: Compromise enables full website defacement, data exfiltration, malware distribution, lateral movement to backend systems, and credential harvesting. Exploitation Likelihood: High. CVSS 9.8 + unauthenticated attack vector + file upload mechanics make this trivially automatable; exploitation likely already in the wild or imminent. RECOMMENDED ACTIONS Immediate (next 4 hours): ...