RCE-баг в плагине Forminator для WordPress угрожает 300 000 сайтов
PatchForminator Forms for WordPressOur summary
A critical remote code execution vulnerability, tracked as CVE-2026-15748 with a CVSS score of 9.8, has been fixed in the Forminator Forms plugin for WordPress. Discovered by security researcher daroo and reported to Wordfence, the flaw allows unauthenticated attackers to bypass file extension checks via MIME-type manipulation, enabling them to upload malicious PHP files through forms containing both File Upload and Select fields. While default configurations often mitigate risk via .htaccess restrictions, sites using custom storage directories remain highly vulnerable to webshell installation and full compromise. The issue affects all versions up to and including 1.56.1, and the fix was introduced in version 1.56.2 released on July 31, 2026; however, approximately half of the over 600,000 installed instances—roughly 300,000 sites—remain on vulnerable versions.
Хакер (xakep.ru) publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.