Forminator WordPress Plugin Carries Critical Flaw Rated 9.8; 600,000 Sites Affected
A newly disclosed vulnerability in the Forminator plugin lets attackers upload malicious files without logging in, putting hundreds of hundreds of WordPress sites at risk of full takeover.

Key points
- Forminator Forms, a WordPress plugin active on more than 600,000 sites, carries a critical flaw tracked as CVE-2026-15748.
- The bug scores 9.8 out of 10 on the Common Vulnerability Scoring System, the industry scale for measuring how dangerous a flaw is.
- An unauthenticated attacker, someone with no account on the site, can upload a malicious PHP file and run their own code on the server.
- Update the plugin immediately, then check upload folders for files you didn't put there.
A critical hole in a widely used WordPress plugin is putting more than 600,000 sites at risk of full takeover by anyone on the internet. No login required.
The plugin is Forminator Forms, which lets site owners build contact forms and quizzes without writing code. A security researcher disclosed the flaw, tracked as CVE-2026-15748, after finding it in the plugin's file-upload handling. It scores 9.8 out of 10 on the CVSS scale. Anything above 9 is treated as critical.
WordPress plugin security has been a recurring concern on this beat. Our 10 August report on BdThemes plugins being hijacked to spawn hidden admin accounts is the fourth such plugin-compromise story we've filed since June.
What can an attacker actually do?
A visitor who has never logged in can upload a booby-trapped PHP script disguised as a normal form attachment. Once that file lands on the server, requesting its URL executes it. Full unauthenticated remote code execution: a stranger, without a password, runs their own commands on your server.
From there the intruder can read the database, plant a backdoor or redirect visitors to scam pages. The realistic worst case isn't defacement; it's a quietly compromised site that nobody notices for weeks.
Who is affected?
Any WordPress site running a vulnerable version of Forminator Forms is exposed. The plugin's official listing shows more than 600,000 active installs. Theme choice and hosting provider don't matter. If the plugin's active, the site's a target.
Forminator didn't properly validate what kind of file was being submitted. PHP scripts, the language WordPress runs on, slipped through as ordinary attachments.
What should site owners do now?
Update through the WordPress dashboard today. A flaw at 9.8 will be scanned for automatically within days of public disclosure; speed matters more than it usually does.
After patching, open the site's uploads folder and look for .php files you didn't place there. Check admin accounts for names you don't recognise. If anything looks wrong, restore from a clean backup predating the disclosure and rotate every password and API key tied to the site.
| Detail | Value |
|---|---|
| Plugin | Forminator Forms |
| Installations | 600,000+ |
| CVE | CVE-2026-15748 |
| CVSS score | 9.8 (critical) |
| Impact | Unauthenticated remote code execution |
Common questions
Do ordinary visitors to an affected site face any danger?
Indirectly, yes. A criminal who takes over a site through this flaw can plant malicious scripts targeting visitors, harvest payment details entered into forms, or redirect people to scam pages. Avoid entering card details on sites that look broken or unfamiliar.
Is there any sign this is being exploited in the wild yet?
No public reports of mass exploitation had surfaced at disclosure, but critical WordPress plugin flaws are typically weaponised within a week. Treat this patch as urgent, not routine.
The detail worth watching isn't the CVSS score; it's how long sites take to actually update. Exploit code for file-upload bypasses circulates fast, and plugins with six-figure install counts are priority targets. If your site runs Forminator, the window for acting before attackers do is short.



