CVE-2026-15748 — WPMU DEV Forminator Forms Select Field Injection Unrestricted File Upload
aretiq.ai | research | CVE-2026-15748 | #ai-security | #rce | #wordpress | #authentication | #vulnerability | #cve | #file-upload | #forminator | #cve-2026-15748
Summary
Aretiq on CVE-2026-15748: Forminator Forms (600k+ installs) lets unauthenticated attackers bypass its file-extension blocklist and upload PHP files for remote code execution; fixed in 1.56.2.
Why it matters
This research provides technical context that security teams can use for monitoring and validation.
- Vendor
- WPMU DEV
- Product
- Forminator Forms plugin for WordPress
- Affected versions
- through 1.56.1; fixed in 1.56.2
- Published
- Collected
Skip to content