DIRAS TAKE
Urgent: public exploit code exists and no fix is yet available for affected versions, so sites using the plugin should assume high risk and take immediate mitigations.
What is CVE-2026-15748?
Unauthenticated attackers can upload arbitrary files to the Forminator Forms – Contact Form, Payment Form & Custom Form Builder WordPress plugin, potentially leading to remote code execution. CVE-2026-15748 affects versions 1.56.1 and earlier; the vulnerability arises from insufficient file-type validation in the plugin's upload handler and a public submission endpoint that can be tricked into accepting attacker-controlled upload configuration. An attacker only needs network access to a site running the vulnerable plugin to exploit this issue. The weakness is classified as CWE-434 (Unrestricted File Upload).
Vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Which versions of wpmudev Forminator Forms – Contact Form, Payment Form & Custom Form Builder are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | 1.56.1 and earlier |
Is CVE-2026-15748 being exploited?
Public exploit code is available.
How to fix CVE-2026-15748
- Deactivate or remove the Forminator Forms plugin until the vendor issues a fixed release.
- If you cannot remove it, disable file uploads and any public submission handlers provided by the plugin.
- Harden upload directories: restrict execution rights and isolate writable paths from the web root.
- Monitor web and application logs for suspicious upload attempts and indicators of compromise and apply the vendor's guidance when published.
Frequently asked questions
Is CVE-2026-15748 being actively exploited?
Public exploit code for CVE-2026-15748 is available; the vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of 2026-09-29, so active exploitation beyond public proof-of-concept cannot be confirmed from these facts.
Which Forminator Forms versions are affected by CVE-2026-15748?
Forminator Forms versions 1.56.1 and earlier are affected according to the vendor-supplied affected range.
Is there a patch for CVE-2026-15748?
No fixed version is listed for CVE-2026-15748 in the provided facts; a vendor patch is not yet available as of 2026-09-29.
Does CVE-2026-15748 require authentication?
No, the vulnerability can be exploited without authentication against the Forminator Forms plugin via a public submission handler.
References
- nvd.nist.gov/vuln/detail/CVE-2026-15748
- cve.org/CVERecord?id=CVE-2026-15748
- wordfence.com/threat-intel/vulnerabilities/id/263ac05d-f1ca-46e3-a43e-3b45eb8066d4?source=cve
- plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/fields/upload.php#L552
- plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/modules/custom-forms/front/front-action.php#L2767
- plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/modules/custom-forms/front/front-action.php#L738
- plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/helpers/helper-fields.php#L3425
- plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/abstracts/abstract-class-field.php#L2308
- plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/admin/classes/class-admin-ajax.php#L1196
- All wpmudev CVEs on CVE Radar
- CVEs published in September 2026