As cited
Copy frozen at (site build).
vulnerabilities
300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
CVE-2026-15748 is an arbitrary file upload vulnerability in a WordPress form plugin that allows unauthenticated attackers to upload executable files. The flaw potentially affects around 300,000 WordPress installations.
Why it matters: WordPress site administrators using this form plugin face immediate risk of remote code execution and should update or disable the plugin without delay.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
CVE-2026-15748 is an arbitrary file upload vulnerability in a WordPress form plugin that allows unauthenticated attackers to upload executable files. The flaw potentially affects around 300,000 WordPress installations.
Why it matters: WordPress site administrators using this form plugin face immediate risk of remote code execution and should update or disable the plugin without delay.
- Source published
- First seen by Cybersecurity Tracker