Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
WordPress Plugin Flaw Puts 300,000 Sites at Risk

WordPress Plugin Flaw Puts 300,000 Sites at Risk

Posted on August 18, 2026 By CWS

A significant security flaw has been identified in the Forminator Forms plugin, a popular tool used on WordPress websites. This vulnerability, classified as CVE-2026-15748 with a critical CVSS score of 9.8, could potentially allow unauthorized users to execute remote code on affected websites, according to cybersecurity firm Defiant.

Understanding the Vulnerability

The flaw is rooted in the handle_file_upload function of the Forminator Forms plugin. This function’s inadequate validation of file types permits attackers to upload malicious executable files. By exploiting this weakness, hackers can manipulate the plugin’s Select field configuration, bypassing the blocklist of file types intended to prevent such breaches.

Defiant describes the issue as a culmination of several security gaps. Attackers can inject their own configuration values through a forged Select field, allowing them to upload harmful files that evade detection by the plugin’s security measures.

Risk and Impact Assessment

In default settings, uploaded files are stored in a directory that blocks PHP execution, providing some protection. However, if a Custom File Upload Storage root is set up, this safeguard is bypassed, and the uploaded PHP code can be executed upon direct request. Such vulnerabilities can lead to complete website takeover through tactics like webshell deployment.

The vulnerability affects all versions of Forminator Forms up to 1.56.1, with a fix issued in version 1.56.2 on July 31. The plugin boasts over 600,000 installations, with approximately half of these running the susceptible version, thereby putting over 300,000 websites at risk.

Preventive Measures and Future Outlook

Despite the absence of any known exploitation of this vulnerability in live attacks, website administrators are strongly advised to update to the latest patched version to safeguard their sites. Regular updates and vigilant monitoring of plugins are crucial steps in preventing similar threats.

This incident underscores the importance of maintaining updated cybersecurity measures and being proactive with software updates. As vulnerabilities are identified and patched, prompt action is necessary to protect digital assets from potential threats.

Security Week News Tags:CVE-2026-15748, Cybersecurity, Defiant, file upload flaw, Forminator Forms, internet security, plugin patching, plugin vulnerability, remote code execution, site compromise, software updates, Webshells, website hacking, website protection, WordPress security

Post navigation

Previous Post: AmnesiaStealer Exploits macOS Browsers for Remote Control
Next Post: Critical VMware Flaw Exploited for Full Infrastructure Control

Related Posts

WordPress Plugin Flaw Puts 300,000 Sites at Risk Critical WordPress Flaws WP2Shell Actively Exploited Security Week News
Google API Keys in Android Apps Risk Data Breach Google API Keys in Android Apps Risk Data Breach Security Week News
Stryker Discovers Malicious File in Iran-Linked Cyberattack Probe Stryker Discovers Malicious File in Iran-Linked Cyberattack Probe Security Week News
Google Researchers Find New Chrome Zero-Day Google Researchers Find New Chrome Zero-Day Security Week News
Apple Releases iOS Updates to Counter Coruna Threats Apple Releases iOS Updates to Counter Coruna Threats Security Week News
Email Security Startup AegisAI Launches With  Million in Funding Email Security Startup AegisAI Launches With $13 Million in Funding Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Red Hat Satellite Flaw: Risk of Root Password Theft
  • Hackers Exploit Software Updates for Credential Theft
  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • October 2026
  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Red Hat Satellite Flaw: Risk of Root Password Theft
  • Hackers Exploit Software Updates for Credential Theft
  • Major Cybersecurity Breaches and AI Threats Uncovered
  • Hackers Exploit Microsoft SQL Server for Data Exfiltration
  • iCloud Email Flaws Allowed Spoofing of Any Address

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark