Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in Forminator Plugin Allows Remote Code Execution

Critical Flaw in Forminator Plugin Allows Remote Code Execution

Posted on August 17, 2026 By CWS

A significant security vulnerability has been identified in the Forminator Forms plugin for WordPress, which is currently active on over 600,000 websites. This flaw, if exploited, can lead to unauthorized code execution, posing a substantial threat to affected sites.

Details of the Forminator Vulnerability

The vulnerability has been cataloged as CVE-2026-15748 and boasts a high CVSS score of 9.8 out of 10. An online security researcher known as ‘daroo’ is credited with the discovery and report of this critical flaw. According to Wordfence, the security company that published the findings, attackers could exploit this vulnerability to upload arbitrary files, including PHP executables, to a compromised site.

Successful exploitation requires the presence of a form with both a File Upload and a Select field on the WordPress site. The vulnerability affects all plugin versions up to 1.56.1, with a fix released in version 1.56.2 on July 31, 2026.

Technical Analysis and Exploitation

The core of the vulnerability lies in the ‘handle_file_upload()’ function, where inadequate file type validation allows unauthorized file uploads. Attackers can utilize this loophole to upload malicious PHP files by submitting forms configured with specific parameters, thereby gaining site control.

While the default setup includes an .htaccess file to prevent PHP execution in the upload directory, custom configurations may lack this protection. If a site administrator has modified the File Upload Storage root, the preventative measure might be absent, allowing execution of the uploaded PHP code.

Additional Security Concerns

In related news, Wordfence also uncovered an authentication bypass vulnerability in the User Profile Builder plugin, affecting over 40,000 installations. This flaw, CVE-2026-15826, allows attackers to log in as the administrator, posing a severe risk to site security. The vulnerability was patched on July 16, 2026, with the deployment of version 3.16.5.

This issue arises from the misuse of the ‘wppb_log_in_user()’ function, which mishandles user registration processes. Specifically, the WordPress system fails to properly handle certain registration errors, inadvertently granting unauthorized access to the main administrator account.

Website administrators are urged to promptly update both plugins to mitigate potential risks and ensure their WordPress installations are secure against these vulnerabilities.

The Hacker News Tags:CVE-2026-15748, CVE-2026-15826, Forminator, plugin update, remote code execution, security flaw, user profile builder, Vulnerability, website security, Wordfence, WordPress

Post navigation

Previous Post: Critical GitLab Flaw Allows Project Deletion Risk
Next Post: Cavern Framework Evolves with New DNS and Google Apps Integration

Related Posts

Google Reports Exploitation of Qualcomm Android Vulnerability Google Reports Exploitation of Qualcomm Android Vulnerability The Hacker News
New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT New EVALUSION ClickFix Campaign Delivers Amatera Stealer and NetSupport RAT The Hacker News
OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps OneLogin Bug Let Attackers Use API Keys to Steal OIDC Secrets and Impersonate Apps The Hacker News
Critical WSO2 API Manager Vulnerability Exploited Critical WSO2 API Manager Vulnerability Exploited The Hacker News
India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse India Orders Messaging Apps to Work Only With Active SIM Cards to Prevent Fraud and Misuse The Hacker News
CISA Adds Two N-able N-central Flaws to Known Exploited Vulnerabilities Catalog CISA Adds Two N-able N-central Flaws to Known Exploited Vulnerabilities Catalog The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Hackers Exploit Software Updates for Credential Theft
  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Hackers Exploit Software Updates for Credential Theft
  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address
  • Fake Zoom Installer on macOS Spreads CloudSyncD Malware

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark