# Forminator WordPress Plugin Exposes 600,000 Sites to Unauthenticated Remote Code Execution


## The Threat


Forminator Forms, one of WordPress's most widely deployed drag-and-drop form builders, has a critical file upload vulnerability that hands unauthenticated attackers a direct path to remote code execution. The flaw — tracked as CVE-2026-15748 and scoring 9.8 on the CVSS scale — allows anyone on the internet to upload a malicious PHP file through a Forminator-powered form and then trigger its execution on the server. No login, no elevated permissions, no social engineering required.


The mechanics are straightforward and brutal: Forminator's file upload handling fails to adequately validate or restrict the types of files accepted through its form fields. An attacker submits a crafted .php file disguised as a legitimate attachment. If the server is configured to execute PHP in the upload directory — a common condition on shared hosts and misconfigured VPS environments — the attacker then issues a single HTTP request to the uploaded file's path and achieves arbitrary code execution under the web server's user context.


From there, the attack surface opens completely. Depending on server configuration and privilege levels, an attacker can read sensitive files (including wp-config.php, which exposes database credentials), install backdoors, pivot into the underlying host, exfiltrate user data, or enroll the server into a botnet. With over 600,000 active installations, the exposure window here is enormous — and because the exploit requires no authentication, automated scanning and mass exploitation are trivially achievable the moment a working proof-of-concept circulates.


## Severity and Impact


| Field | Detail |

|---|---|

| CVE | CVE-2026-15748 |

| CVSS Score | 9.8 (Critical) |

| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |

| CWE | CWE-434: Unrestricted Upload of File with Dangerous Type |

| Attack Vector | Network |

| Attack Complexity | Low |

| Authentication Required | None |

| User Interaction | None |

| Impact | Full confidentiality, integrity, and availability compromise |


The 9.8 score is not inflated. The combination of network reachability, zero authentication, low complexity, and full-triad impact places this firmly among the most dangerous classes of web application vulnerability. The only reason it doesn't score a perfect 10.0 is that exploitation success still depends partly on server-side configuration — specifically whether the upload directory permits PHP execution.


## Affected Products


  • Forminator Forms plugin for WordPress
  • - All versions prior to the patched release (patch version to be confirmed via the WordPress plugin repository)

    - Affects installations with file upload fields enabled on public-facing forms

    - Elevated risk on shared hosting environments and servers where /wp-content/uploads/ is PHP-executable


    > Note: Sites using Forminator solely for non-file-upload forms (contact forms, polls, quizzes without file input) may have reduced exposure, but the plugin itself remains vulnerable and should be updated regardless.


    ## Mitigations


    Immediate actions — in priority order:


  • Update Forminator immediately. Check the WordPress plugin dashboard or the official WordPress.org plugin page for the patched version. Enable automatic updates for security releases if you haven't already.

  • Audit your upload directory configuration. Verify that /wp-content/uploads/ and any custom upload paths cannot execute PHP. Add an .htaccess rule to block PHP execution in upload directories if your host supports it:
  • ```apache

    <FilesMatch "\.php$">

    Deny from all

    </FilesMatch>

    ```


  • Review recent form submissions. If you've been running Forminator with file upload fields on a public form, inspect recent submissions for unexpected .php, .phtml, .phar, or double-extension files (e.g., image.php.jpg). Check server access logs for requests to /wp-content/uploads/ that returned a 200 response on non-image file types.

  • Restrict file upload types at the application layer. Even after patching, enforce strict allowlists in Forminator's file upload field settings — permit only the specific extensions your use case requires (e.g., pdf, jpg, png).

  • Deploy a WAF rule. If you operate a web application firewall (Cloudflare, Wordfence, Sucuri, etc.), enable or push rules that block PHP file uploads through form submissions. Most managed WAF providers will push signatures quickly after a disclosure like this.

  • Network segmentation for high-value targets. Organizations running WordPress on internet-facing infrastructure alongside internal systems should ensure the web tier cannot reach internal network segments in the event of a compromise.

  • Incident response posture. If you cannot patch immediately, consider temporarily disabling all Forminator file upload fields or taking affected forms offline until the update is applied. Leaving a 9.8 unauthenticated RCE exposed in production is not a calculated risk — it's an open door.

  • ## References


  • WordPress Plugin Repository — Forminator: https://wordpress.org/plugins/forminator/
  • National Vulnerability Database (NVD): https://nvd.nist.gov/vuln/detail/CVE-2026-15748
  • WPMU DEV (Forminator developer): https://wpmudev.com/project/forminator-pro/
  • OWASP — Unrestricted File Upload (CWE-434): https://owasp.org/www-community/vulnerabilities/Unrestricted_File_Upload

  • ---


    ## HackWire Analysis


    File upload vulnerabilities are not new. They're not exotic. And that's precisely what makes this disclosure so damning.


    CVE-2026-15748 is a textbook CWE-434 — a class of bug that's been on the OWASP Top 10 radar for over a decade. The fix is well-understood: validate file type server-side, never trust client-supplied MIME types, store uploads outside the web root or strip PHP execution from upload directories, and enforce strict extension allowlisting. These aren't cutting-edge defensive techniques; they're first-year web security fundamentals.


    Yet here we are, with a 600,000-install plugin shipping without them adequately implemented.


    What this really surfaces is the structural problem with the WordPress plugin ecosystem. Plugins are built by vendors of wildly varying security maturity, deployed by site owners who often lack the expertise to audit them, and updated inconsistently — if at all. Forminator is a legitimate, actively maintained plugin from WPMU DEV, not an abandoned one. That a critical file upload flaw made it into a product of this scale and usage suggests either insufficient security testing in the development process or that file upload handling was treated as a solved problem and never revisited.


    The exploitation risk here is not theoretical. Automated scanners will identify vulnerable Forminator installations within days of a public PoC. Shared hosting environments — where thousands of WordPress sites live on the same underlying server — are particularly exposed: a single compromised site can become a pivot point.


    For defenders: if you run WordPress at any scale, Forminator belongs on your immediate patch list. For the broader ecosystem: this is a case study in why plugin security audits, automated SAST in development pipelines, and mandatory security-focused code review before major releases aren't optional extras for widely deployed software — they're table stakes.


    — HackWire Editorial


    ---


    ## Related Coverage


  • Read more in our [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) coverage
  • Cross-reference with [Breaches](https://www.hackwire.news/category/breaches) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)