DEV Community

Cover image for Unauthenticated RCE Vulnerability Patched in Forminator Forms Plugin
BeyondMachines for BeyondMachines

Posted on Originally published at beyondmachines.net

Unauthenticated RCE Vulnerability Patched in Forminator Forms Plugin

Summary

WPMU DEV patched a critical vulnerability (CVE-2026-15748) in the Forminator Forms plugin that allowed unauthenticated attackers to upload and execute PHP files. The flaw can lead to full remote code execution and site compromise.

Take Action:

If you use the Forminator Forms plugin on your WordPress site, update it to version 1.56.2 or later ASAP away: attackers can take over the whole site without logging in. After updating, check your upload folders for any unfamiliar PHP files. If you can't update yet, delete any forms that use both File Upload and Select fields.


Read the full article on BeyondMachines


This article was originally published on BeyondMachines

Top comments (0)