Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons

Social Media

Hackers News Hackers News
  • CyberSecurity News
  • Threats
  • Attacks
  • Vulnerabilities
  • Breaches
  • Comparisons
Search the Site
Popular Searches:
technology Amazon AI
Recent Posts
Critical WordPress Plugin Bug Exposes 600,000 Sites to File Upload Attacks
August 18, 2026
Critical VMware ESXi Vulnerability Lets Attackers Gain Root and Persistent SSH Access
August 18, 2026
Critical GitLab GraphQL Vulnerability Lets Attackers Delete Projects
August 18, 2026
Home/Vulnerabilities/Critical WordPress Plugin Bug Exposes 600,000 Sites to File Upload Attacks
Vulnerabilities

Critical WordPress Plugin Bug Exposes 600,000 Sites to File Upload Attacks

Key Takeaways A critical vulnerability in the Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious files. Over 600,000 WordPress sites using Forminator Forms...

Marcus Rodriguez
Marcus Rodriguez
August 18, 2026 3 Min Read
4 0

Key Takeaways

  • A critical vulnerability in the Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious files.
  • Over 600,000 WordPress sites using Forminator Forms versions 1.56.1 and earlier are at risk.
  • The flaw, identified as CVE-2026-15748, has a CVSS score of 9.8, indicating severe impact.
  • A patch is available in Forminator Forms version 1.56.2; immediate updates are strongly recommended.

Critical WordPress Plugin Flaw Puts 600,000+ Sites at Risk

A severe security vulnerability affecting the popular Forminator Forms plugin for WordPress could enable unauthorized attackers to upload arbitrary PHP files. This critical flaw potentially grants full control over compromised websites, posing a significant threat to a vast number of installations.

Table Of Content

  • Key Takeaways
  • Critical WordPress Plugin Flaw Puts 600,000+ Sites at Risk
  • Technical Breakdown of the Vulnerability
  • What You Should Do

The vulnerability, designated CVE-2026-15748, impacts all Forminator Forms versions up to and including 1.56.1. It carries a CVSS severity rating of 9.8, underscoring its critical nature. With more than 600,000 active installations, Forminator Forms is widely used for creating various interactive elements, including contact forms, payment gateways, polls, quizzes, and file upload functionalities. WordPress administrators who have not yet applied the latest security update remain exposed to potential exploitation.

Technical Breakdown of the Vulnerability

The flaw was reported through the Wordfence bug bounty program by security researcher daroo, who received a $2,048 reward for the discovery. Wordfence confirmed the report on July 14, 2026, and promptly informed the Forminator development team the same day. The vendor subsequently released a corrective update, Forminator Forms version 1.56.2, on July 31, 2026.

The vulnerability stems from an issue in Forminator’s file-upload handling mechanism. Attackers can exploit this by injecting a manipulated upload configuration into published forms that utilize the “Select” field. During processing, the plugin incorrectly accepts attacker-controlled values for parameters such as the upload field name, field type, and specific file-handling settings. This malicious request then tricks the plugin into treating the forged data as a legitimate upload configuration.

Crucially, this attack also circumvents the plugin’s built-in file-extension filtering designed to block dangerous executable file types like PHP. While Forminator employs a blocklist for this purpose, researchers discovered that its filtering logic relies on exact matching against file-extension keys. An attacker can bypass this by using a pattern such as ph(p) instead of the blocked php extension. WordPress still interprets ph(p) as a .php file extension, yet Forminator’s blocklist fails to identify and remove it. By combining this forged configuration with an appropriate MIME type, such as text/x-php, an attacker can successfully upload a PHP payload that passes the plugin’s validation checks.

Typically, uploaded files are stored in a directory protected by an .htaccess rule, which prevents PHP execution. However, sites configured with custom file-upload storage locations may lack this crucial protection under specific circumstances. If a malicious PHP file is uploaded to an executable, web-accessible path, an attacker could directly access and execute it, running arbitrary commands on the server.

Successful exploitation of this vulnerability could lead to severe consequences, including remote code execution, deployment of webshells, theft of sensitive WordPress credentials, unauthorized database access, installation of malware, or complete compromise of the affected website.

What You Should Do

  • Update Immediately: All administrators using Forminator Forms must update their plugin to version 1.56.2 or later without delay.
  • Review Form Configurations: Inspect existing form configurations, particularly those involving file uploads, for any unusual or suspicious settings.
  • Inspect Upload Directories: Manually review file upload directories for any unfamiliar or suspicious PHP files that may have been uploaded.
  • Verify Execution Protection: Ensure that all directories designated for file uploads are adequately protected against server-side code execution, especially if custom storage locations are in use.

Disclaimer: HackersRadar reports on cybersecurity threats and incidents for informational and awareness purposes only. We do not engage in hacking activities, data exfiltration, or the hosting or distribution of stolen or leaked information. All content is based on publicly available sources.

Tags:

AttackCVEExploitMalwareSecurityVulnerability

Share Article

Marcus Rodriguez

Marcus Rodriguez

Marcus is a security researcher and investigative journalist with expertise in vulnerability research, bug bounties, and cloud security. Since 2017, Marcus has been breaking stories on critical vulnerabilities affecting major platforms. His investigative work has led to the disclosure of numerous security flaws and improved defenses across the industry. Marcus is an active participant in bug bounty programs and has been recognized for responsible disclosure practices. He holds multiple security certifications and regularly speaks at industry events.

Previous Post

Critical VMware ESXi Vulnerability Lets Attackers Gain Root and Persistent SSH Access

No Comment! Be the first one.

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Popular Posts
Claude AI code enabled ransomware gang to steal LDAP passwords, backdoor VPNs
August 18, 2026
Pokémon Center Data Breach Exposes Customer PII to Hackers
August 18, 2026
Best Software-Defined Perimeter (SDP) Solutions of 2024
August 17, 2026
Top Authors
Marcus Rodriguez
Marcus Rodriguez
David kimber
David kimber
Jennifer sherman
Jennifer sherman
Let's Connect
156k
2.25m
285k

Related Posts

Jennifer sherman
By Jennifer sherman
Threats

GlassWorm Attacks macOS via Malicious VS Code…

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Attacks

ClickFix Attack Hides Malicious Code via Stegan Security

January 1, 2026
Sarah simpson
By Sarah simpson
Vulnerabilities

MongoBleed Detector Tool Released to Detect MongoDB Vulnerability(CVE-2025-14847)

January 1, 2026
Emy Elsamnoudy
By Emy Elsamnoudy
Breaches

Conti Ransomware Gang Leaders & Infrastructure Exposed

January 1, 2026
Hackers News Hackers News
  • [email protected]

Quick Links

  • Contact Us
  • Privacy Policy
  • Terms of service

Categories

Attacks
Breaches
Comparisons
CyberSecurity News
Threats
Vulnerabilities

Let's keep in touch

receive fresh updates and breaking cyber news every day and week!

All Rights Reserved by HackersRadar ©2026

Follow Us