Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
- Posted on August 17, 2026
- By The Hacker News
- 0 Views
- 1 min read
In brief
Generating AI summary…
Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads
Forminator CVE-2026-15748 lets unauthenticated attackers upload PHP files and reach RCE on sites using vulnerable form configurations.