Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
The Hacker News
1 hour from now

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

By info@thehackernews.com (The Hacker News)

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias "

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.