Critical Vulnerability in Forminator Forms WordPress Plugin Exposes 600,000+ Sites to Remote Takeover
A severe security flaw in the Forminator Forms WordPress plugin (CVE-2026-15748, CVSS 9.8) allows unauthenticated attackers to upload malicious PHP files, potentially leading to full website compromise. The vulnerability affects versions 1.56.1 and earlier of the plugin, which is used by over 600,000 active installations for building forms, polls, quizzes, and payment systems.
Discovered by security researcher daroo through the Wordfence bug bounty program, the flaw was reported and validated on July 14, 2026. The vendor released a patch in Forminator Forms version 1.56.2 on July 31, 2026.
The exploit stems from improper file-upload handling, where attackers can forge upload configurations via the plugin’s Select field. By manipulating values such as the field name, type, and file settings, malicious requests bypass the plugin’s blocklist-based extension filtering. For example, using ph(p) instead of the blocked php extension evades detection, as WordPress still interprets it as a valid PHP file.
While uploaded files are typically stored in a directory protected by .htaccess rules, sites with custom upload paths may lack this safeguard. If a PHP file lands in an executable, web-accessible location, attackers can trigger remote code execution (RCE), deploy webshells, steal credentials, or gain full control of the site.
Administrators are urged to update to the latest version and audit form configurations, upload directories, and server-side execution permissions.
Source: https://cybersecuritynews.com/wordpress-forminator-plugin-vulnerability/
WPMU DEV cybersecurity rating report: https://www.rankiteo.com/company/wpmu-dev
"id": "WPM1787049574",
"linkid": "wpmu-dev",
"type": "Vulnerability",
"date": "7/2026",
"severity": "100",
"impact": "5",
"explanation": "Attack threatening the organization's existence"
{'affected_entities': [{'customers_affected': '600,000+ websites',
'industry': 'Web Development, Content Management '
'Systems',
'location': 'Global',
'name': 'Forminator Forms WordPress Plugin Users',
'size': '600,000+ active installations',
'type': 'Software/Plugin'}],
'attack_vector': 'Remote',
'customer_advisories': 'Administrators are urged to update to the latest '
'version and audit form configurations, upload '
'directories, and server-side execution permissions.',
'data_breach': {'file_types_exposed': ['PHP files']},
'date_detected': '2026-07-14',
'date_resolved': '2026-07-31',
'description': 'A severe security flaw in the Forminator Forms WordPress '
'plugin (CVE-2026-15748, CVSS 9.8) allows unauthenticated '
'attackers to upload malicious PHP files, potentially leading '
'to full website compromise. The vulnerability affects '
'versions 1.56.1 and earlier of the plugin, which is used by '
'over 600,000 active installations for building forms, polls, '
'quizzes, and payment systems.',
'impact': {'operational_impact': 'Potential full website compromise, remote '
'code execution (RCE), credential theft, or '
'deployment of webshells',
'systems_affected': '600,000+ WordPress sites using Forminator '
'Forms plugin'},
'investigation_status': 'Resolved',
'lessons_learned': 'Improper file-upload handling and blocklist-based '
'extension filtering can be bypassed, leading to critical '
'vulnerabilities. Custom upload paths may lack safeguards '
'like .htaccess rules, increasing risk.',
'post_incident_analysis': {'corrective_actions': 'Patch released to fix the '
'vulnerability, stricter '
'file-upload validation '
'recommended.',
'root_causes': 'Improper file-upload handling and '
'blocklist-based extension '
'filtering in the Forminator Forms '
'WordPress plugin.'},
'recommendations': 'Update to Forminator Forms version 1.56.2 or later. Audit '
'form configurations, upload directories, and server-side '
'execution permissions. Implement stricter file-upload '
'validation and monitoring.',
'references': [{'source': 'Wordfence bug bounty program'}],
'response': {'containment_measures': 'Patch released (Forminator Forms '
'version 1.56.2)',
'remediation_measures': 'Update to the latest version, audit '
'form configurations, upload '
'directories, and server-side execution '
'permissions',
'third_party_assistance': 'Wordfence bug bounty program'},
'title': 'Critical Vulnerability in Forminator Forms WordPress Plugin Exposes '
'600,000+ Sites to Remote Takeover',
'type': 'Vulnerability Exploitation',
'vulnerability_exploited': 'CVE-2026-15748 (Improper file-upload handling in '
'Forminator Forms WordPress plugin)'}