FOFA[verified]@fofabotDisclosure
The tweet announces CVE-2026-15748, a high‑severity (CVSS 9.8) unauthenticated arbitrary file upload flaw in WordPress Forminator Forms plugin (≤1.56.1), with FOFA query results and a SecurityWeek reference, but provides no PoC, exploit code, active exploitation evidence, or patch information.
Rıdvan Yağlı[verified]@ridvanyagliDisclosure
A critical RCE (CVE-2026-15748) in the Forminator Forms WordPress plugin has been disclosed, affecting versions 1.56.1 and earlier, with a patch available in version 1.56.2; no evidence of active exploitation or PoC is provided.
Ahmedkhan[verified]@Ahmed___khaanPatch
A critical CVE affecting Forminator is highlighted, urging administrators to promptly update the plugin to mitigate the risk of remote code execution.
Teegra 🧝♀️𝕏[verified]@TeeegraDisclosure
The post announces a newly identified CVE (CVE‑2026‑15748) affecting Forminator Forms with high severity and describes its technical details, but does not provide any PoC, exploit code, or patch information.
Aikido Community Japan[verified]@AikidoCommJPPatch
The post discloses CVE-2026-15748, a critical unauthenticated RCE in Forminator Forms that allows PHP file uploads via specific form configurations; it announces the fix (v1.56.2) and urges site owners to update.
MagicWP[verified]@magicwp_ioPatch
The text announces a vulnerability in Forminator that permits unauthenticated PHP uploads and provides guidance on how to detect exposure and apply patches.
DFIR Radar[verified]@DFIR_RadarDisclosure
The post discloses a high‑severity vulnerability (CVSS 9.8) in Forminator Forms that allows unauthenticated PHP file uploads via injected fields and blocklist circumvention.
Nitin Gavhane[verified]@NitinGavhane_Disclosure
The post announces a critical arbitrary file upload vulnerability in Forminator Forms (CVE‑2026‑15748), warns of potential remote code execution, and directs users to update to the patched version 1.56.2.