CRITICAL
9.8 CVE-2026-15748 Published 18 Aug 2026
Forminator WordPress Plugin Arbitrary File Upload Vulnerability
Worried this affects one of your servers?
The Forminator Forms plugin for WordPress is vulnerable to arbitrary file upload in all versions up to and including 1.56.1.
The flaw exists in the handle_file_upload function, where insufficient file type validation allows bypassing the dangerous-extension blocklist using pipe-alternative MIME type keys. A public submission handler also trusts attacker-controlled upload field configuration injected via a forged Select field value.
- Affected versions: all versions up to and including 1.56.1
- Attackers: unauthenticated
- Impact: upload of potentially executable files, leading to remote code execution
Reference: CVE-2026-15748 on NVD
← Back to Security News