CYBERSECURITYTRACKER
TRACKING
Permanent story citation

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 4592

As cited

Copy frozen at (site build).

vulnerabilities

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

CVE-2026-15748 is an arbitrary file upload vulnerability in a WordPress form plugin that allows unauthenticated attackers to upload executable files. The flaw potentially affects around 300,000 WordPress installations.

Why it matters: WordPress site administrators using this form plugin face immediate risk of remote code execution and should update or disable the plugin without delay.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

CVE-2026-15748 is an arbitrary file upload vulnerability in a WordPress form plugin that allows unauthenticated attackers to upload executable files. The flaw potentially affects around 300,000 WordPress installations.

Why it matters: WordPress site administrators using this form plugin face immediate risk of remote code execution and should update or disable the plugin without delay.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary