CVE-2026-15748 —— WPMU DEV Forminator Forms 选择字段注入导致不受限制的文件上传
aretiq.ai | 研究 | CVE-2026-15748 | #ai-security | #rce | #wordpress | #authentication | #vulnerability | #cve | #file-upload | #forminator | #cve-2026-15748
摘要
Aretiq 分析 CVE-2026-15748:Forminator Forms(60 万+安装量)信任 Select 字段中客户端提供的键值,未认证攻击者可绕过扩展名黑名单上传可执行 PHP 文件,实现远程代码执行;1.56.2 已修复。
为什么值得关注
这项研究提供技术背景,便于安全团队开展监测和验证。
- 厂商
- WPMU DEV
- 产品
- Forminator Forms plugin for WordPress
- 受影响版本
- through 1.56.1; fixed in 1.56.2
- 发布时间
- 收录时间
Skip to content