CYBERSECURITYTRACKER
TRACKING
Permanent story citation

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4556

As cited

Copy frozen at (site build).

vulnerabilities

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical remote code execution vulnerability in the Forminator WordPress plugin affects over 600,000 installations. The flaw, tracked as CVE-2026-15748 with a CVSS score of 9.8, permits unauthenticated attackers to upload malicious PHP files and execute arbitrary code on vulnerable sites.

Why it matters: WordPress administrators running Forminator must patch or disable the plugin immediately to prevent complete site compromise; this vulnerability requires no authentication and has high exploitability.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical remote code execution vulnerability in the Forminator WordPress plugin affects over 600,000 installations. The flaw, tracked as CVE-2026-15748 with a CVSS score of 9.8, permits unauthenticated attackers to upload malicious PHP files and execute arbitrary code on vulnerable sites.

Why it matters: WordPress administrators running Forminator must patch or disable the plugin immediately to prevent complete site compromise; this vulnerability requires no authentication and has high exploitability.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary