CVE-2026-15748Disclosure

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 22 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 45 mentions across 6 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 18 signals
  • Technical details provided in 35 signals
  • Disclosure: 18 classified signals
  • Peaked 4d ago at 22 mentions (2026-08-18); latest day: 1
  • 45 total mentions across 6 days

Deep dive

Activity timeline45 mentions / 6d
06111722Mentions · 2026-08-17: 7Mentions · 2026-08-18: 22Mentions · 2026-08-19: 9Mentions · 2026-08-20: 5Mentions · 2026-08-24: 1Mentions · 2026-08-26: 1PoC Mentioned / Linked · 2026-08-17: 1PoC Mentioned / Linked · 2026-08-18: 1PoC Mentioned / Linked · 2026-08-19: 2PoC Mentioned / Linked · 2026-08-20: 2Exploit Tool / Code · 2026-08-19: 1Exploit Tool / Code · 2026-08-20: 1Active Exploitation · 2026-08-17: 1Active Exploitation · 2026-08-18: 4Active Exploitation · 2026-08-19: 1Patch / Workaround · 2026-08-17: 5Patch / Workaround · 2026-08-18: 8Patch / Workaround · 2026-08-19: 3Patch / Workaround · 2026-08-20: 1Patch / Workaround · 2026-08-26: 1Technical Details · 2026-08-17: 7Technical Details · 2026-08-18: 17Technical Details · 2026-08-19: 6Technical Details · 2026-08-20: 3Technical Details · 2026-08-24: 1Technical Details · 2026-08-26: 108-1708-1808-1908-2008-2408-26
Signal classification6 categories
Disclosure
1840.0%
Patch
1226.7%
Active Exploitation
613.3%
General
511.1%
Exploit
36.7%
PoC
12.2%
Referenced assets26 URLs
By indicator
Classification over time
DateTotalLabels
2026-08-177
Active Exploitation1Disclosure2Patch4
2026-08-1822
Active Exploitation4Disclosure9Exploit1General2Patch6
2026-08-199
Active Exploitation1Disclosure3Exploit1General2Patch2
2026-08-205
Disclosure2Exploit1General1PoC1
2026-08-241
Disclosure1
2026-08-261
Disclosure1
Full discourse20 posts
  • The Hacker News@TheHackersNews
    Disclosure

    🚨 Forminator flaw can give unauthenticated attackers RCE. CVE-2026-15748 affects 600,000+ active WordPress installs. On susceptible forms, attackers can upload malicious PHP files and potentially take over the site. Read: https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html

    Post summary

    The article announces a critical RCE flaw in the Forminator WordPress plugin (CVE‑2026‑15748) that allows unauthenticated attackers to upload malicious PHP files and potentially take over affected sites.

    45552079051.9K
    2.4M followersView on X
  • FOFA@fofabot
    Disclosure

    ⚠️⚠️ CVE-2026-15748 (CVSS 9.8): Unauthenticated arbitrary file upload in WordPress Forminator Forms plugin (≤1.56.1) 🔗FOFA Link: https://en.fofa.info/result?qbase64=YXBwPSJXb3JkUHJlc3MtRm9ybWluYXRvciI= 🎯115.3K+ Results are found on http://en.fofa.info in the past year. FOFA Query: app="WordPress-Forminator" 🔖Refer: https://www.securityweek.com/300000-wordpress-sites-potentially-exposed-to-hacking-due-to-form-plugin-flaw/ #OSINT #FOFA #CyberSecurity #Vulnerability

    Post summary

    The tweet announces CVE-2026-15748, a high‑severity (CVSS 9.8) unauthenticated arbitrary file upload flaw in WordPress Forminator Forms plugin (≤1.56.1), with FOFA query results and a SecurityWeek reference, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    116040154.2K
    14.8K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Disclosure

    🔴 600 bin+ WordPress sitesini etkileyen kritik RCE açığı! Forminator Forms eklentisinde CVE-2026-15748 CVSS: 9.8 — Critical olarak takip edilen kritik bir güvenlik açığı keşfedildi. Saldırganlar, kimlik doğrulaması gerektirmeden, uygun şekilde yapılandırılmış formlarda dosya yükleme mekanizmasını kötüye kullanarak PHP dosyaları yükleyebilir ve uzaktan kod çalıştırabilir (RCE). Başarılı istismar, WordPress sitesinin tamamen ele geçirilmesine yol açabilir. Açık, Forminator Forms eklentisinin 1.56.1 ve önceki sürümlerini etkiliyor. Güvenlik güncellemesi 1.56.2 sürümünde yayınlandı. ⚠️ Özellikle File Upload + Select alanlarını kullanan formlar ve Custom File Upload Storage yapılandırmaları ayrıca kontrol edilmeli.

    Post summary

    A critical RCE (CVE-2026-15748) in the Forminator Forms WordPress plugin has been disclosed, affecting versions 1.56.1 and earlier, with a patch available in version 1.56.2; no evidence of active exploitation or PoC is provided.

    00023171.9K
    2.4K followersView on X
  • Ahmedkhan@Ahmed___khaan
    Patch

    🚨 A serious vulnerability in adding Forminator threatens more than 600,000 WordPress sites. The CVE-2026-15748 vulnerability allows unverified attackers to upload malicious PHP files through affected templates, which could lead to remote execution and full site takeover. Website administrators are advised to immediately update Forminator to the latest secure version.

    Post summary

    A critical CVE affecting Forminator is highlighted, urging administrators to promptly update the plugin to mitigate the risk of remote code execution.

    140205981
    9.6K followersView on X
  • Teegra 🧝‍♀️𝕏@Teeegra
    Disclosure

    یک آسیب‌پذیری امنیتی بحرانی در افزونه وردپرس «Forminator Forms» با بیش از ۶۰۰ هزار نصب فعال کشف شده است که می‌تواند منجر به اجرای کد دلخواه (arbitrary code execution) روی سایت‌های آسیب‌پذیر شود. این آسیب‌پذیری با شناسه CVE-2026-15748 و امتیاز ۹.۸ از ۱۰ در سیستم امتیازدهی CVSS، به مهاجمان احراز هویت‌نشده اجازه می‌دهد فایل‌های دلخواه از جمله فایل‌های اجرایی PHP را بارگذاری کرده و کنترل کامل سایت را در دست بگیرند. این نقص ناشی از اعتبارسنجی ناکافی نوع فایل در تابع «handle_file_upload()» است و تمام نسخه‌های ۱.۵۶.۱ و پیش از آن را تحت تأثیر قرار می‌دهد.

    Post summary

    The post announces a newly identified CVE (CVE‑2026‑15748) affecting Forminator Forms with high severity and describes its technical details, but does not provide any PoC, exploit code, or patch information.

    01090810
    19.9K followersView on X
  • National CERT/CC@CERT_UG
    Patch

    🚨 Patch Now | August 18, 2026 Today's vulnerabilities are as follows; - GitLab (CVE-2026-19478, CVSS 9.4) - Zoom for Windows (CVE-2026-53412, CVSS 9.8) - WordPress Forminator Forms (CVE-2026-15748, CVSS 9.8) https://cert.ug | #CyberSafeUG https://t.co/yYzCFkUhrZ

    Post summary

    The tweet lists three high‑severity CVEs with CVSS scores and urges users to apply patches to mitigate the risks.

    02040166
    1.5K followersView on X
  • absholi7ly@absholi7ly
    PoC

    PoC CVE-2026-15748 Forminator Unauthenticated RCE. #CVE202615748 #Forminator #WordPress #InfoSec #RCE https://t.co/0d4DHEp56x

    Post summary

    The post announces a proof‑of‑concept for CVE‑2026‑15748, exposing an unauthenticated remote code execution vulnerability in the Forminator WordPress plugin.

    00032295
    308 followersView on X
  • Aikido Community Japan@AikidoCommJP
    Patch

    WordPressのフォームプラグイン、Forminator Formsに未認証RCE。 CVE-2026-15748。CVSS 9.8。 Forminatorは60万以上のサイトで使われている。 条件は、File UploadとSelectの両方を持つフォームが存在すること。 攻撃者はログイン不要。 細工したリクエストでPHPファイルをアップロードし、最終的にサイト上でコード実行まで到達できる。 根っこはかなり教科書的。 危険な拡張子をブロックしているが、判定が「完全一致」。 MIMEタイプのキーをパイプ区切りにすることでチェックをすり抜けられる。 さらにSelectフィールドを偽装すると、アップロード先の設定まで攻撃者側から操作できる。 つまり、 「危険な拡張子は弾いているから大丈夫」 だけでは防げなかった。 修正版は1.56.2。 Forminatorを使っているサイトは、まずバージョン確認と更新を。 同じ記事では、User Profile Builderの認証バイパス CVE-2026-15826(CVSS 9.8)も報告されている。 こちらはWP_Errorを確認する前にabsint()へ渡したことで整数1に丸められ、結果としてID=1の管理者としてログインできてしまう問題。 修正版は3.16.5。 WordPressは本体だけでなく、プラグイン側の更新確認も重要です。 #WordPress #Forminator #脆弱性 #RCE #AppSec #WebSecurity

    Post summary

    The post discloses CVE-2026-15748, a critical unauthenticated RCE in Forminator Forms that allows PHP file uploads via specific form configurations; it announces the fix (v1.56.2) and urges site owners to update.

    010221.1K
    860 followersView on X
  • MagicWP@magicwp_io
    Patch

    CVE-2026-15748 lets unauthenticated visitors upload PHP via Forminator (≤1.56.1), but it only bites if a form pairs File Upload with Select, and PHP can run in your uploads folder. We broke down how to check exposure and patch. https://magicwp.io/blog/cve-2026-15748-forminator-file-upload #WordPressSecurity #CVE

    Post summary

    The text announces a vulnerability in Forminator that permits unauthenticated PHP uploads and provides guidance on how to detect exposure and apply patches.

    00040106
    15 followersView on X
  • DFIR Radar@DFIR_Radar
    Disclosure

    CVE-2026-15748 (CVSS 9.8) in Forminator Forms allows unauthenticated PHP file upload via chained Select-field injection and blocklist bypass. Hunt WordPress upload dirs for .php/.phtml files and check custom storage roots for missing .htaccess. #DFIR_Radar https://t.co/4DcoxPF7DF

    Post summary

    The post discloses a high‑severity vulnerability (CVSS 9.8) in Forminator Forms that allows unauthenticated PHP file uploads via injected fields and blocklist circumvention.

    10002191
    1.9K followersView on X
  • Nitin Gavhane@NitinGavhane_
    Disclosure

    CVE ALERT — CVE-2026-15748 A critical arbitrary file upload vulnerability affects Forminator Forms, a WordPress plugin with 600,000+ active installations. Unauthenticated attackers can potentially upload executable files, creating a path to remote code execution and full site compromise under affected conditions. 🔴 Affected: Forminator ≤ 1.56.1 🟢 Fixed: 1.56.2 If you run Forminator, update immediately. Plugin ecosystems remain one of the biggest attack surfaces in WordPress. #CVE #CVE202615748 #WordPress #AppSec #BugBounty #CyberSecurity #Vulnerability #InfoSec

    Post summary

    The post announces a critical arbitrary file upload vulnerability in Forminator Forms (CVE‑2026‑15748), warns of potential remote code execution, and directs users to update to the patched version 1.56.2.

    01020183
    1.4K followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] EGE-GH-voHnlXt [CRITICAL/PoC] Linked: CVE-2026-15748 cve-2026-15748 🔗 https://exploitgrid.net/exploits/b55fe148-40ea-4992-ba0e-68a29fd26787

    Post summary

    A PoC exploit for CVE-2026-15748 has been published on ExploitGrid, indicating that functional exploit code is available but there is no evidence of active exploitation or patch information.

    1001042
    35 followersView on X
  • Aretiq.AI@AretiqAI
    Exploit

    ARETIQ Daily Vulnerability Bulletin — August 18, 2026 🔴 CRITICAL: CVE-2026-15748 (wpmudev/forminator_forms_–_contact_form,_payment_form_&_custom_form_builder) AAS 12.6 — exploit available 21 vulnerabilities — CRITICAL: 1, HIGH: 20 Full bulletin: https://aretiq.ai/bulletins/2026-08-18/

    Post summary

    CVE‑2026‑15748, a critical flaw in wpmudev/forminator_forms_, has an available exploit, indicating it is actionable and potentially exploitable in the wild.

    0002083
    226 followersView on X
  • 🕵️vito.@vit0corleonne
    Disclosure

    600.000'den fazla aktif Forminator Forms eklentisinin kurulu olduğu wordpress sistemleri etkileyen ve skoru 9.8 olan yeni bir güvenlik açığı keşfedilmiş.(CVE-2026-15748). Saldırganlar , sisteme bir php dosyası yükleyerek tüm sistemi ele geçirebilecek bir rce çalıştırabiliyorlar.

    Post summary

    A new critical CVE-2026-15748 affecting Forminator Forms plugin is disclosed, with a CVSS score of 9.8, allowing attackers to upload a PHP file and achieve remote code execution on WordPress sites.

    00020129
    90 followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    Patch

    CVE-2026-15748, a CVSS 9.8 flaw in Forminator Forms, lets unauthenticated attackers upload PHP files for pre-auth RCE. Update to 1.56.2 now. #CVE202615748 #Forminator #WordPress #RCE #FileUpload #WordPressSecurity https://securityonline.info/cve-2026-15748-forminator-rce/

    Post summary

    A high‑severity RCE vulnerability (CVE-2026-15748) in Forminator Forms allows unauthenticated PHP file uploads; the issue is remediated by updating to version 1.56.2.

    01010428
    12.8K followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    CVE-2026-15748 (CVSS 9.8 Critical): Unauthenticated arbitrary file upload in Forminator Forms affects 600,000+ WordPress sites, enabling remote code execution via PHP webshell delivery. - CVE-2026-15748, CVSS 9.8. All Forminator Forms versions up to 1.56.1 are vulnerable. Patch is version 1.56.2, released July 31, 2026. Exploitation requires a published form with both a File Upload field and a Select field present simultaneously. - The attack chain is a logic flaw, not a simple bypass. An attacker submits a forged Select field value carrying a spoofed Upload record, injecting attacker-controlled field configuration into field_data_array before validation runs. The upload handler then trusts that configuration, including a custom MIME type and extension list. - The blocklist strips the literal "php" key but not regex-style alternatives. Supplying the pattern ph(p)|text/x-php bypasses exact-key matching in forminator_allowed_mime_types(), while WordPress's extension matcher still resolves ph(p) as .php, letting the file pass validation and land on disk. - RCE is achieved when the site uses a Custom File Upload Storage root. That directory lacks the .htaccess guard (written only during a specific load context), so a direct HTTP request executes the uploaded PHP webshell. Default upload directories are partially mitigated by .htaccess, but custom roots are not. #DFIR_Radar

    Post summary

    The post discloses a critical file‑upload flaw in Forminator Forms, describes the detailed exploitation path, and announces that a patch (v1.56.2) is available.

    10010300
    1.8K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    WordPress Forminator プラグインの脆弱性 CVE-2026-15748 が FIX:偽造コンフィグ注入の可能性 https://iototsecnews.jp/2026/08/18/critical-wordpress-plugin-vulnerability-exposes-600000-sites-to-file-upload-attacks/ Forminator Forms に存在する、高深刻度の脆弱性 CVE-2026-15748 について紹介する記事です。この問題は、ファイルアップロード処理の不備により、認証されていない第三者から偽造設定の注入や危険な拡張子のチェック回避を許してしまう点に起因します。悪用された場合、悪意のある PHP ファイルのアップロード/リモートコード実行/Web シェルの展開/不正アクセスによるサイト全体の制御奪取といった重大な影響へつながる恐れがあります。安全な運用に向けて、プラグインをバージョン 1.56.2 以降へ速やかに更新することや、アップロード先の権限および不審ファイルの点検を実施することが推奨されます。 #CVE202615748 #Forminator #Vulnerability #WordPress

    Post summary

    The article discloses CVE‑2026‑15748 in WordPress Forminator, explaining a file‑upload flaw that could enable remote code execution, and advises updating to version 1.56.2 or newer to mitigate the risk.

    00010192
    510 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ ExploitGrid Daily Threat Digest Critical Exploits disclosed today: EGE-GH-bnhF7il ( CVE-2020-14882 ) EGE-GH-seDznkg ( CVE-2026-65400 ) EGE-GH-voHnlXt ( CVE-2026-15748 ) EGE-GH-UkSlg0M ( CVE-2026-19598 ) EGE-GH-IxgnwCb ( CVE-2025-62593 ) ..🧵👇

    Post summary

    The digest enumerates several CVE identifiers labeled as ‘Critical Exploits’ but offers no additional details, proofs, or remediation guidance.

    1000056
    35 followersView on X
  • The CyberSec Guru@thecybersecguru
    Disclosure

    🚨 CRITICAL WORDPRESS SECURITY ALERT Two CVEs put vulnerable WordPress sites at serious risk: 🔴 CVE-2026-15748 — Forminator RCE 🔴 CVE-2026-15826 — User Profile Builder Auth Bypass ⚠️ CVSS 9.8 Critical One can lead to unauthenticated RCE. The other can enable admin takeover. Patch NOW 👇 https://thecybersecguru.com/news/cve-2026-15748-forminator-rce-cve-2026-15826-user-profile-builder/

    Post summary

    The post announces two critical WordPress CVEs, highlights their RCE and auth bypass vulnerabilities with a CVSS score of 9.8, and urges immediate patching, but does not provide exploit code or detailed patch instructions.

    00010136
    1.2K followersView on X
  • Frontiera Tech@FrontieraTechIT
    Active Exploitation

    🛡️ CYBER BULLETIN | 2026/08/18 🚨 1. CISA adds critical Ray RCE to KEV catalog CISA flagged CVE-2025-62593 (CVSS 9.4) in the popular open-source Ray AI/ML framework as actively exploited. The flaw enables browser-based remote code execution via DNS rebinding on Firefox and Safari, primarily hitting developers running local or network-adjacent instances. Federal agencies must remediate by Aug 20. 2. Critical GitLab GraphQL flaw lets unauthenticated attackers delete projects GitLab patched CVE-2026-19478 (CVSS 9.4) affecting CE/EE versions. Under certain conditions, unauthenticated attackers can remotely modify or delete public projects and user data via a GraphQL directive. Self-managed instances should upgrade immediately to 18.11.11, 19.0.8, 19.1.6 or 19.2.4. 3. Suspected China-nexus APT exploits VMware vCenter flaw for ransomware Threat actors are actively abusing CVE-2026-59310 (CVSS 9.8 directory traversal) in vCenter Syslog Server, just days after the July 29 patch. Campaign hit \~361 systems across 47 countries, leading to root access, ESXi compromise and Babuk-derived ransomware (.babyk). Patch and hunt for indicators urgently. 4. Critical unauthenticated RCE in Forminator WordPress plugin CVE-2026-15748 (CVSS 9.8) in Forminator Forms (≤1.56.1) allows unauthenticated attackers to upload executable PHP files on sites with specific form configurations, potentially leading to full site takeover. The plugin has 600,000+ active installs — update to 1.56.2 or later now. 5. SafePal hardware wallet breach exposes data of nearly 40,000 customers An authorization flaw in an order-tracking plugin leaked names, emails, shipping addresses, phone numbers and purchase details. No wallet keys or funds were compromised, but the data is already circulating on cybercrime forums, raising phishing and physical risk concerns. #Cybersecurity #CISA #NIST

    Post summary

    The bulletin highlights several critical CVEs that are actively exploited in the wild and urges immediate patching or upgrading to mitigate the risks.

    10000165
    67 followersView on X

Explore more