Advisory Forminator Forms web-app User Profile Builder WordPress rce
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
CVE Tools coverage
Wordfence has disclosed a critical vulnerability, designated CVE-2026-15748, in the Forminator Forms WordPress plugin that allows unauthenticated attackers to achieve remote code execution. This flaw stems from insufficient file type validation in the handle_file_upload() function, enabling malicious users to upload executable PHP files if specific form fields are present. The issue affects all versions prior to and including 1.56.1 and carries a CVSS score of 9.8. A separate authentication bypass vulnerability, CVE-2026-15826, was also identified in the User Profile Builder plugin, allowing unauthorized administrative access under certain configurations.