Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Plugin Flaw Puts 300,000 Sites at Risk

WordPress Plugin Flaw Puts 300,000 Sites at Risk

Posted on August 18, 2026 By CWS

A significant security flaw has been identified in the Forminator Forms plugin, a popular tool used on WordPress websites. This vulnerability, classified as CVE-2026-15748 with a critical CVSS score of 9.8, could potentially allow unauthorized users to execute remote code on affected websites, according to cybersecurity firm Defiant.

Understanding the Vulnerability

The flaw is rooted in the handle_file_upload function of the Forminator Forms plugin. This function’s inadequate validation of file types permits attackers to upload malicious executable files. By exploiting this weakness, hackers can manipulate the plugin’s Select field configuration, bypassing the blocklist of file types intended to prevent such breaches.

Defiant describes the issue as a culmination of several security gaps. Attackers can inject their own configuration values through a forged Select field, allowing them to upload harmful files that evade detection by the plugin’s security measures.

Risk and Impact Assessment

In default settings, uploaded files are stored in a directory that blocks PHP execution, providing some protection. However, if a Custom File Upload Storage root is set up, this safeguard is bypassed, and the uploaded PHP code can be executed upon direct request. Such vulnerabilities can lead to complete website takeover through tactics like webshell deployment.

The vulnerability affects all versions of Forminator Forms up to 1.56.1, with a fix issued in version 1.56.2 on July 31. The plugin boasts over 600,000 installations, with approximately half of these running the susceptible version, thereby putting over 300,000 websites at risk.

Preventive Measures and Future Outlook

Despite the absence of any known exploitation of this vulnerability in live attacks, website administrators are strongly advised to update to the latest patched version to safeguard their sites. Regular updates and vigilant monitoring of plugins are crucial steps in preventing similar threats.

This incident underscores the importance of maintaining updated cybersecurity measures and being proactive with software updates. As vulnerabilities are identified and patched, prompt action is necessary to protect digital assets from potential threats.

Security Week News Tags:CVE-2026-15748, Cybersecurity, Defiant, file upload flaw, Forminator Forms, internet security, plugin patching, plugin vulnerability, remote code execution, site compromise, software updates, Webshells, website hacking, website protection, WordPress security

Post navigation

Previous Post: AmnesiaStealer Exploits macOS Browsers for Remote Control
Next Post: Critical VMware Flaw Exploited for Full Infrastructure Control

Related Posts

Surveillance Firm Bypasses SS7 Protections to Retrieve User Location Surveillance Firm Bypasses SS7 Protections to Retrieve User Location Security Week News
BreachForums Owner Sent to Prison in Resentencing  BreachForums Owner Sent to Prison in Resentencing  Security Week News
WhatsApp Introduces Usernames for Enhanced Privacy WhatsApp Introduces Usernames for Enhanced Privacy Security Week News
Wytec Expects Significant Financial Loss Following Website Hack Wytec Expects Significant Financial Loss Following Website Hack Security Week News
US Seeks Forfeiture of .74M in Cryptocurrency Tied to North Korean IT Workers US Seeks Forfeiture of $7.74M in Cryptocurrency Tied to North Korean IT Workers Security Week News
Flaw in Industrial Computer Maker’s UEFI Apps Enables Secure Boot Bypass on Many Devices Flaw in Industrial Computer Maker’s UEFI Apps Enables Secure Boot Bypass on Many Devices Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • AI-Powered Crypto Scam Targets Phone Numbers to Find Victims
  • Xpander Secures $7.5M for AI Platform Expansion
  • Typosquatting Campaign Targets RubyGems Users’ Data
  • Critical VMware Flaw Exploited for Full Infrastructure Control
  • WordPress Plugin Flaw Puts 300,000 Sites at Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • AI-Powered Crypto Scam Targets Phone Numbers to Find Victims
  • Xpander Secures $7.5M for AI Platform Expansion
  • Typosquatting Campaign Targets RubyGems Users’ Data
  • Critical VMware Flaw Exploited for Full Infrastructure Control
  • WordPress Plugin Flaw Puts 300,000 Sites at Risk

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark