# Critical Forminator flaw exposes vulnerable WordPress sites to code execution

_Monday, August 17, 2026 at 2:22 PM EDT · Security · Latest · Tier 1 — Major_

![Critical Forminator flaw exposes vulnerable WordPress sites to code execution — Primary](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5Jfag1_E06odK7mkATjCOSPdD_fHy2kcYYHfi9fDNTsk0CRkV2yJD0Uz4MV82XjbMR5QNyK3Akw5Ysf0N7fDQ3DwApNb5Tf9R4axktScKF3UZlMVtrY3ulTzrYjFviMA8HmIUCBZhxmR59TtnJ7xf-B_iJtl3SWiBZAFbOfhUoldNdZX0sOStx6ULNMSZ/s1700-e365/wordpress-flaw.jpg)

A disclosed flaw in the Forminator Forms WordPress plugin can allow unauthenticated attackers to upload executable PHP files and potentially take over susceptible sites. Wordfence rates CVE-2026-15748 at CVSS 9.8 and says it affects versions through 1.56.1; version 1.56.2, released July 31, addresses it. Exploitation requires a form with both File Upload and Select fields. Default upload storage may block PHP execution, but custom storage roots may lack that safeguard.

## Sources

- [The Hacker News](https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html)

---
Canonical: https://techandbusiness.org/newswire/WzNlfbWn2jSzQbWYiohGiB
Retrieved: 2026-08-18T00:21:59.806Z
Publisher: Tech & Business (techandbusiness.org)
