Thousands of WordPress sites are affected by a new critical vulnerability in Forminator Forms, a popular plugin with more than 600,000 active installations. The flaw, documented as CVE-2026-15748, has received a CVSS score of 9.8/10, as it could allow unauthenticated attackers to upload malicious files and, under certain circumstances, execute arbitrary code on the server.

The vulnerability was discovered by a researcher using the pseudonym "daroo", while Wordfence analyzed how it can be exploited. The problem is located in the management mechanism file upload and is related to insufficient checking of the type of files submitted through a form.
Forminator Forms: When is there a real risk?
The attack cannot be carried out on every Forminator Forms installation. A basic requirement is that the website has a form that includes both a file upload field and a Select field. As long as this condition is met, an unauthenticated user can attempt to bypass the restrictions and upload a specially crafted file.
See also: Forminator plugin: Critical vulnerability affects thousands of WordPress sites
The issue affects versions up to and including 1.56.1, while the patched version 1.56.2 was released on July 31, 2026. For WordPress administrators, updating is not just a standard maintenance process, but a critical protection measure, as remote code execution can be the starting point for a complete site compromise.

From an upload to full occupancy
According to Wordfence's analysis, the vulnerability lies in the handle_file_upload(). The process does not adequately verify the file type, allowing an attacker to manipulate the relevant parameters.
The attack exploits block list dangerous extension, combined with alternative MIME values and the configuration of the upload field. With a properly crafted submission, the attacker can trick the system into accepting a PHP file.
The critical point is that such a file is not just unwanted content. If the web server allows its execution, the attacker can execute commands with the application's privileges. From there, it is possible to modify files, install malicious code, create accounts , or gain access to data.
See also: New WordPress Pre-Auth XSS may lead to PHP code execution
Additional risk from custom settings
By default, Forminator stores uploaded files in a directory protected by .htaccess, restricting PHP execution. However, this protection is not a given in every installation.
If the administrator has set a Custom File Upload Storage root, the specified protection file may not be created in time. In this case, a malicious PHP file can be directly accessed via the web server and executed with a simple call to its address.

What should administrators do?
The vulnerability reminds us that WordPress plugins are a critical part of the attack surface. Administrators should immediately update Forminator Forms to version 1.56.2 or later.
See also: LiteSpeed Cache plugin: Hackers gain control of WordPress sites via vulnerability
At the same time, it is necessary to check for suspicious files, unknown administrator accounts and unusual changes in website behavior. Regularly updating plugins, restricting permissions and monitoring logs can significantly reduce the risk. In an environment where a plugin can turn from a useful tool into a full-fledged entry point for an attacker, promptly applying available patches remains the most important line of defense.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
