CVE-2026-15748 – Critical Remote Code Execution in Forminator WordPress Plugin

Key takeaways

  • Critical ( CVSS 9.8 ) unauthenticated file upload leading to remote code execution.
  • Affects Forminator Forms plugin ≤ 1.56.1, deployed on ~600 k active WordPress sites.
  • Exploits observed within days of disclosure; active exploitation reported on 2026‑08‑17, 2026‑08‑18, and 2026‑08‑19.
  • Immediate patch to version 1.56.2 required; mitigate by disabling file‑upload forms and monitoring.
  • Track live threat signals on the VulnSocial CVE page.

Overview

A remote code execution (RCE) flaw was disclosed in the Forminator Forms WordPress plugin (maintained by WPMU DEV). The vulnerability allows an attacker with no authentication to upload a malicious PHP file through any form that uses the plugin’s file‑upload field. Once the file is stored on the server, the attacker can execute arbitrary code, effectively taking over the WordPress site.

The issue was publicly disclosed on 2026‑08‑17 and quickly attracted attention from the security community. Within 48 hours, multiple threat‑intel feeds reported active exploitation attempts targeting vulnerable installations.


Technical Details

  • The vulnerable code resides in the plugin’s handle_file_upload() routine, which fails to enforce a strict whitelist on uploaded file extensions and does not validate the destination path.
  • Attackers can craft a multipart POST request that includes a payload such as shell.php and bypass the existing checks.
  • The uploaded file is written to a web‑accessible directory (e.g., wp‑content/uploads/), making it directly reachable via HTTP.
  • Upon request, the PHP payload runs with the same privileges as the web server, enabling full remote code execution.
  • The flaw exists in all releases up to 1.56.1. It was fixed in 1.56.2, where the upload handler now:
    • Enforces a whitelist of safe extensions (.jpg, .png, .gif).
    • Stores files outside the web root when possible.
    • Adds a nonce check to ensure the request originates from a legitimate form submission.

Proof‑of‑concept (PoC) code was circulated on the same day of disclosure, and at least one public exploit script appeared on 2026‑08‑19 (see the VulnSocial timeline).


Severity & Impact

MetricValue
CVSS9.8 (Critical)
VectorNetwork, Remote, Unauthenticated
ImpactFull site compromise – attacker can execute arbitrary commands, deface sites, exfiltrate data, or install ransomware.
CWECWE‑434 (Unrestricted Upload of File with Dangerous Type)

Given the unauthenticated nature of the attack and the large install base (≈ 600 k sites), the risk rating is Critical.


Affected Products

  • Vendor: WPMU DEV
  • Product: Forminator Forms plugin for WordPress
  • Vulnerable versions: ≤ 1.56.1

For the complete list of affected versions and distribution details, see the VulnSocial CVE page.


Actionable Insights

  • Monitor web server access logs for suspicious POST requests to wp‑admin/admin-ajax.php or any endpoint that includes action=forminator_upload_file.
  • Deploy a Web Application Firewall (WAF) rule to block .php (or other executable) uploads to the wp‑content/uploads/ directory.
  • Enable WordPress security hardening plugins that restrict file types and enforce MIME‑type validation.
  • Audit existing uploads: locate any PHP files in the uploads folder and remove them immediately.
  • Threat intel: Use the VulnSocial timeline to watch for spikes in exploitation attempts.

Remediation & Mitigation

  1. Update the Forminator plugin to 1.56.2 or later. This is the official patch that resolves the upload validation flaw.
  2. If an immediate update is not possible, disable all Forminator file‑upload fields via the plugin settings or by removing the shortcode [forminator_form] from pages.
  3. Restrict PHP execution in the uploads directory by adding a .htaccess rule:
    <FilesMatch "\.php$">
        Order allow,deny
        Deny from all
    </FilesMatch>
    
  4. Implement a WAF rule (e.g., ModSecurity) to reject multipart requests that contain a file with a .php extension.
  5. Conduct a post‑incident review: scan the filesystem for rogue PHP files, rotate compromised credentials, and apply the principle of least privilege to the web‑server user.

Bottom Line

CVE-2026-15748 is a Critical RCE vulnerability in the Forminator Forms WordPress plugin that enables unauthenticated attackers to upload and execute malicious PHP code. With active exploitation already observed, the only safe course of action is to apply the official patch (v1.56.2) immediately, disable unnecessary file‑upload features, and monitor for suspicious activity using the live threat feed on the VulnSocial platform.


References