HomeSecurityForminator Forms: Critical vulnerability affects WordPress sites

Forminator Forms: Critical vulnerability affects WordPress sites

Thousands of WordPress sites are affected by a new critical vulnerability in Forminator Forms, a popular plugin with more than 600,000 active installations. The flaw, documented as CVE-2026-15748, has received a CVSS score of 9.8/10, as it could allow unauthenticated attackers to upload malicious files and, under certain circumstances, execute arbitrary code on the server.

Forminator Forms

The vulnerability was discovered by a researcher using the pseudonym "daroo", while Wordfence analyzed how it can be exploited. The problem is located in the management mechanism file upload and is related to insufficient checking of the type of files submitted through a form.

Forminator Forms: When is there a real risk?

The attack cannot be carried out on every Forminator Forms installation. A basic requirement is that the website has a form that includes both a file upload field and a Select field. As long as this condition is met, an unauthenticated user can attempt to bypass the restrictions and upload a specially crafted file.

See also: Forminator plugin: Critical vulnerability affects thousands of WordPress sites

The issue affects versions up to and including 1.56.1, while the patched version 1.56.2 was released on July 31, 2026. For WordPress administrators, updating is not just a standard maintenance process, but a critical protection measure, as remote code execution can be the starting point for a complete site compromise.

Forminator Forms: Critical vulnerability affects WordPress sites

From an upload to full occupancy

According to Wordfence's analysis, the vulnerability lies in the handle_file_upload(). The process does not adequately verify the file type, allowing an attacker to manipulate the relevant parameters.

The attack exploits block list dangerous extension, combined with alternative MIME values ​​and the configuration of the upload field. With a properly crafted submission, the attacker can trick the system into accepting a PHP file.

The critical point is that such a file is not just unwanted content. If the web server allows its execution, the attacker can execute commands with the application's privileges. From there, it is possible to modify files, install malicious code, create accounts , or gain access to data.

See also: New WordPress Pre-Auth XSS may lead to PHP code execution

Additional risk from custom settings

By default, Forminator stores uploaded files in a directory protected by .htaccess, restricting PHP execution. However, this protection is not a given in every installation.

If the administrator has set a Custom File Upload Storage root, the specified protection file may not be created in time. In this case, a malicious PHP file can be directly accessed via the web server and executed with a simple call to its address.

Forminator WordPress - SecNews.gr

What should administrators do?

The vulnerability reminds us that WordPress plugins are a critical part of the attack surface. Administrators should immediately update Forminator Forms to version 1.56.2 or later.

See also: LiteSpeed ​​Cache plugin: Hackers gain control of WordPress sites via vulnerability

At the same time, it is necessary to check for suspicious files, unknown administrator accounts and unusual changes in website behavior. Regularly updating plugins, restricting permissions and monitoring logs can significantly reduce the risk. In an environment where a plugin can turn from a useful tool into a full-fledged entry point for an attacker, promptly applying available patches remains the most important line of defense.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS