HackerFeeds

CyberSecurity News

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

The Hacker News
· August 17, 2026

AI summary

A critical security flaw in the Forminator Forms WordPress plugin can be exploited to achieve arbitrary code execution on vulnerable sites. The plugin has over 600,000 active installations, making it a significant target. The vulnerability is rated 9.8 out of 10.0 on the CVSS scoring system and is tracked as CVE-2026-15748. It was discovered by a security researcher and can be exploited via malicious PHP uploads, allowing for unauthenticated remote code execution. The flaw poses a significant risk to sites using the plugin.

Read the full article at The Hacker Newsthehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html

This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.