Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Plugin Flaw Risks 600,000 Sites with Attacks

WordPress Plugin Flaw Risks 600,000 Sites with Attacks

Posted on August 18, 2026 By CWS

A severe security vulnerability identified in the Forminator Forms plugin for WordPress has put upwards of 600,000 websites at risk of unauthorized file uploads and potential site takeovers.

Details of the Security Flaw

The vulnerability, known as CVE-2026-15748, impacts versions 1.56.1 and earlier of Forminator Forms, earning a critical CVSS score of 9.8. This drag-and-drop plugin is widely utilized for creating various forms, including contact and payment forms, making the flaw particularly concerning.

With the potential for attackers to upload malicious PHP files, site administrators who haven’t implemented the latest updates are urged to act swiftly to secure their platforms.

Discovery and Response

Security researcher daroo, through the Wordfence bug bounty program, initially reported the vulnerability. Following swift validation on July 14, 2026, Wordfence coordinated with the Forminator development team to address the issue, leading to the release of a patched version, 1.56.2, on July 31, 2026.

The flaw allows attackers to manipulate the file-upload configuration of vulnerable forms, bypassing security measures designed to block dangerous file types.

Technical Exploitation and Risks

By exploiting Forminator’s file-upload system, attackers can inject a fake upload configuration, tricking the plugin into treating malicious files as legitimate uploads. This bypasses the plugin’s blocklist, which uses exact matches for file extensions, by deploying obscure patterns like ph(p) instead of php, which WordPress still recognizes as executable.

Files uploaded in this manner can be placed in directories lacking .htaccess protection, allowing attackers to execute arbitrary commands, potentially leading to remote code execution or complete site compromise.

Site administrators are advised to update to version 1.56.2 immediately and review form setups and upload directories to ensure no malicious PHP files are present and executable.

By taking these steps, administrators can safeguard their sites against potential threats posed by this critical vulnerability.

Cyber Security News Tags:CVE-2026-15748, file upload attacks, Forminator Forms, plugin vulnerability, remote code execution, security flaw, site security, website protection, Wordfence, WordPress

Post navigation

Previous Post: Critical Security Flaw in GitLab Resolved
Next Post: AmnesiaStealer Exploits macOS Browsers for Remote Control

Related Posts

Hackers Launched 8.1 Million Attack Sessions to React2Shell Vulnerability Hackers Launched 8.1 Million Attack Sessions to React2Shell Vulnerability Cyber Security News
EtherRAT Malware Propagation via Remote Tasks on Windows EtherRAT Malware Propagation via Remote Tasks on Windows Cyber Security News
APT36 Hackers Attacking Indian Government Entities to Steal Login Credentials APT36 Hackers Attacking Indian Government Entities to Steal Login Credentials Cyber Security News
Critical SonicWall SSL VPN Vulnerability Let Attackers Trigger DoS Attack Critical SonicWall SSL VPN Vulnerability Let Attackers Trigger DoS Attack Cyber Security News
Microsoft August 2026 Security Patch Addresses Critical Vulnerabilities Microsoft August 2026 Security Patch Addresses Critical Vulnerabilities Cyber Security News
Critical Vulnerability in Claude Cowork Sandbox Exposed Critical Vulnerability in Claude Cowork Sandbox Exposed Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Critical VMware Flaw Exploited for Full Infrastructure Control
  • WordPress Plugin Flaw Puts 300,000 Sites at Risk
  • AmnesiaStealer Exploits macOS Browsers for Remote Control
  • WordPress Plugin Flaw Risks 600,000 Sites with Attacks
  • Critical Security Flaw in GitLab Resolved

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Critical VMware Flaw Exploited for Full Infrastructure Control
  • WordPress Plugin Flaw Puts 300,000 Sites at Risk
  • AmnesiaStealer Exploits macOS Browsers for Remote Control
  • WordPress Plugin Flaw Risks 600,000 Sites with Attacks
  • Critical Security Flaw in GitLab Resolved

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark