• PoC PUBLIC

CVE-2026-15748: unauthenticated arbitrary file upload in wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder

Unauthenticated attackers can upload arbitrary files to the Forminator Forms – Contact Form, Payment Form & Custom Form Builder WordPress plugin, potentially leading to remote code execution. CVE-2026-15748 affects versions 1.56.1 and earlier; the vulnerability arises from insufficient file-type validation in the plugin's upload handler and a public submission endpoint that can be tricked into accepting attacker-controlled upload configuration. An attacker only needs network access to a site running the vulnerable plugin to exploit this issue.

Published Updated Source: CVE Program, NVD, FIRST EPSS

CVSS 3.1
9.8CRITICAL
EPSS
0.06138
CWE
CWE-434
KEV DUE DATE
Not listed
PATCH
Not yet

DIRAS TAKE

Urgent: public exploit code exists and no fix is yet available for affected versions, so sites using the plugin should assume high risk and take immediate mitigations.

What is CVE-2026-15748?

Unauthenticated attackers can upload arbitrary files to the Forminator Forms – Contact Form, Payment Form & Custom Form Builder WordPress plugin, potentially leading to remote code execution. CVE-2026-15748 affects versions 1.56.1 and earlier; the vulnerability arises from insufficient file-type validation in the plugin's upload handler and a public submission endpoint that can be tricked into accepting attacker-controlled upload configuration. An attacker only needs network access to a site running the vulnerable plugin to exploit this issue. The weakness is classified as CWE-434 (Unrestricted File Upload).

Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Which versions of wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder are affected?

BRANCHAFFECTEDFIXED
1.x1.56.1 and earlier

Is CVE-2026-15748 being exploited?

Public exploit code is available.

How to fix CVE-2026-15748

  1. Deactivate or remove the Forminator Forms plugin until the vendor issues a fixed release.
  2. If you cannot remove it, disable file uploads and any public submission handlers provided by the plugin.
  3. Harden upload directories: restrict execution rights and isolate writable paths from the web root.
  4. Monitor web and application logs for suspicious upload attempts and indicators of compromise and apply the vendor's guidance when published.

Frequently asked questions

Is CVE-2026-15748 being actively exploited?

Public exploit code for CVE-2026-15748 is available; the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-29, so active exploitation beyond public proof-of-concept cannot be confirmed from these facts.

Which Forminator Forms versions are affected by CVE-2026-15748?

Forminator Forms versions 1.56.1 and earlier are affected according to the vendor-supplied affected range.

Is there a patch for CVE-2026-15748?

No fixed version is listed for CVE-2026-15748 in the provided facts; a vendor patch is not yet available as of 2026-09-29.

Does CVE-2026-15748 require authentication?

No, the vulnerability can be exploited without authentication against the Forminator Forms plugin via a public submission handler.

References