Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CVE-2026-15748 — WPMU DEV Forminator Forms Select Field Injection Unrestricted File Upload

Summary

Aretiq on CVE-2026-15748: Forminator Forms (600k+ installs) lets unauthenticated attackers bypass its file-extension blocklist and upload PHP files for remote code execution; fixed in 1.56.2.

Why it matters

This research provides technical context that security teams can use for monitoring and validation.
Vendor
WPMU DEV
Product
Forminator Forms plugin for WordPress
Affected versions
through 1.56.1; fixed in 1.56.2
Published
Collected

original ↗

Related coverage

back