CyberSecurity News
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
AI summary
A critical security flaw in the Forminator Forms WordPress plugin can be exploited to achieve arbitrary code execution on vulnerable sites. The plugin has over 600,000 active installations, making it a significant target. The vulnerability is rated 9.8 out of 10.0 on the CVSS scoring system and is tracked as CVE-2026-15748. It was discovered by a security researcher and can be exploited via malicious PHP uploads, allowing for unauthenticated remote code execution. The flaw poses a significant risk to sites using the plugin.
This is an AI-generated brief aggregated by HackerFeeds for convenience and grounded in the source’s own summary; the related CVE, threat-group and country data is from HackerFeeds’ own indexes. The original article is the authoritative source — all rights belong to The Hacker News.

