CVE Tools
Back to feed
Advisory Forminator Forms web-app User Profile Builder WordPress rce

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

Wordfence has disclosed a critical vulnerability, designated CVE-2026-15748, in the Forminator Forms WordPress plugin that allows unauthenticated attackers to achieve remote code execution. This flaw stems from insufficient file type validation in the handle_file_upload() function, enabling malicious users to upload executable PHP files if specific form fields are present. The issue affects all versions prior to and including 1.56.1 and carries a CVSS score of 9.8. A separate authentication bypass vulnerability, CVE-2026-15826, was also identified in the User Profile Builder plugin, allowing unauthorized administrative access under certain configurations.