
Critical RCE Vulnerability Discovered in Forminator WordPress Plugin Affecting 600,000+ Sites
CybersecurityVulnerabilitiesWordPressExploits
A critical security flaw (CVE-2026-15748) has been disclosed in the Forminator Forms WordPress plugin, which has over 600,000 active installations. The vulnerability, rated 9.8 on the CVSS scoring system, allows unauthenticated remote code execution (RCE) via malicious PHP file uploads. The issue was identified and reported by an unnamed security researcher. No specific exploitation timeline or affected plugin versions were provided. The flaw enables attackers to execute arbitrary code on vulnerable WordPress sites.