CVE-2026-15748 – Critical Remote Code Execution in Forminator WordPress Plugin
Key takeaways
- Critical ( CVSS 9.8 ) unauthenticated file upload leading to remote code execution.
- Affects Forminator Forms plugin ≤ 1.56.1, deployed on ~600 k active WordPress sites.
- Exploits observed within days of disclosure; active exploitation reported on 2026‑08‑17, 2026‑08‑18, and 2026‑08‑19.
- Immediate patch to version 1.56.2 required; mitigate by disabling file‑upload forms and monitoring.
- Track live threat signals on the VulnSocial CVE page.
Overview
A remote code execution (RCE) flaw was disclosed in the Forminator Forms WordPress plugin (maintained by WPMU DEV). The vulnerability allows an attacker with no authentication to upload a malicious PHP file through any form that uses the plugin’s file‑upload field. Once the file is stored on the server, the attacker can execute arbitrary code, effectively taking over the WordPress site.
The issue was publicly disclosed on 2026‑08‑17 and quickly attracted attention from the security community. Within 48 hours, multiple threat‑intel feeds reported active exploitation attempts targeting vulnerable installations.
Technical Details
- The vulnerable code resides in the plugin’s
handle_file_upload()routine, which fails to enforce a strict whitelist on uploaded file extensions and does not validate the destination path. - Attackers can craft a multipart POST request that includes a payload such as
shell.phpand bypass the existing checks. - The uploaded file is written to a web‑accessible directory (e.g.,
wp‑content/uploads/), making it directly reachable via HTTP. - Upon request, the PHP payload runs with the same privileges as the web server, enabling full remote code execution.
- The flaw exists in all releases up to 1.56.1. It was fixed in 1.56.2, where the upload handler now:
- Enforces a whitelist of safe extensions (
.jpg,.png,.gif). - Stores files outside the web root when possible.
- Adds a nonce check to ensure the request originates from a legitimate form submission.
- Enforces a whitelist of safe extensions (
Proof‑of‑concept (PoC) code was circulated on the same day of disclosure, and at least one public exploit script appeared on 2026‑08‑19 (see the VulnSocial timeline).
Severity & Impact
| Metric | Value |
|---|---|
| CVSS | 9.8 (Critical) |
| Vector | Network, Remote, Unauthenticated |
| Impact | Full site compromise – attacker can execute arbitrary commands, deface sites, exfiltrate data, or install ransomware. |
| CWE | CWE‑434 (Unrestricted Upload of File with Dangerous Type) |
Given the unauthenticated nature of the attack and the large install base (≈ 600 k sites), the risk rating is Critical.
Affected Products
- Vendor: WPMU DEV
- Product: Forminator Forms plugin for WordPress
- Vulnerable versions: ≤ 1.56.1
For the complete list of affected versions and distribution details, see the VulnSocial CVE page.
Actionable Insights
- Monitor web server access logs for suspicious
POSTrequests towp‑admin/admin-ajax.phpor any endpoint that includesaction=forminator_upload_file. - Deploy a Web Application Firewall (WAF) rule to block
.php(or other executable) uploads to thewp‑content/uploads/directory. - Enable WordPress security hardening plugins that restrict file types and enforce MIME‑type validation.
- Audit existing uploads: locate any PHP files in the uploads folder and remove them immediately.
- Threat intel: Use the VulnSocial timeline to watch for spikes in exploitation attempts.
Remediation & Mitigation
- Update the Forminator plugin to 1.56.2 or later. This is the official patch that resolves the upload validation flaw.
- If an immediate update is not possible, disable all Forminator file‑upload fields via the plugin settings or by removing the shortcode
[forminator_form]from pages. - Restrict PHP execution in the uploads directory by adding a
.htaccessrule:<FilesMatch "\.php$"> Order allow,deny Deny from all </FilesMatch> - Implement a WAF rule (e.g., ModSecurity) to reject multipart requests that contain a file with a
.phpextension. - Conduct a post‑incident review: scan the filesystem for rogue PHP files, rotate compromised credentials, and apply the principle of least privilege to the web‑server user.
Bottom Line
CVE-2026-15748 is a Critical RCE vulnerability in the Forminator Forms WordPress plugin that enables unauthenticated attackers to upload and execute malicious PHP code. With active exploitation already observed, the only safe course of action is to apply the official patch (v1.56.2) immediately, disable unnecessary file‑upload features, and monitor for suspicious activity using the live threat feed on the VulnSocial platform.
References
- https://vulnsocial.com/cve/CVE-2026-15748 – VulnSocial CVE detail page (real‑time indicators, exploit timeline, patch information).
- https://vulnsocial.com – VulnSocial home page for broader threat intelligence.
