Critical Vulnerability Exposes 300,000 WordPress Sites to Hacking via Form Plugin Flaw

www.news4hackers.com-critical-vulnerability-exposes-300-000-wordpress-sites-to-hacking-via-form-plugin-flaw-critical-vulnerability-exposes-300-000-wordpress-sites-to-hacking-via-form-plugin-flaw

A critical security flaw in the Forminator Forms plugin for WordPress has been identified, exposing potentially 300,000 websites to remote code execution (RCE) risks.

Critical Security Flaw in Forminator Forms Plugin

The vulnerability, designated CVE-2026-15748 with a CVSS score of 9.8, stems from inadequate file type validation within the handle_file_upload function of the widely used form builder plugin.

Vulnerability Details

This flaw allows unauthenticated attackers to upload malicious files, enabling execution of arbitrary code on affected systems. The vulnerability arises from a combination of weaknesses, including the ability to manipulate form configurations through forged Select field entries.

Exploitation Mechanism

Attackers can bypass the plugin’s restriction on dangerous file types by exploiting discrepancies in MIME type validation. Specifically, the blocklist relies on exact-key matching, which is circumvented by alternative MIME type keys.

Additionally, the public submission handler trusts user-controlled upload configurations injected via manipulated form fields. When exploited, this flaw could lead to full system compromise, as attackers could deploy webshells or other malicious payloads.

Patch and Affected Versions

The issue affects all versions of the plugin up to 1.56.1, with a patch released in version 1.56.2 on July 31. The plugin’s extensive adoption—over 600,000 installations—means that approximately half of these sites remain vulnerable, translating to more than 300,000 potentially exposed websites.

Security Recommendations

No evidence of active exploitation in the wild has been reported to date. The flaw highlights the risks associated with arbitrary file upload vulnerabilities, which often serve as entry points for broader attacks. Security researchers emphasize the importance of updating to the patched version to mitigate risks.

The vulnerability underscores the need for rigorous input validation and secure configuration practices in web application components. Organizations using the Forminator Forms plugin are advised to apply the latest update immediately to prevent potential breaches.



About Author

en_USEnglish