Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
3823 articles · 205569 vulns · 37/41 feeds (7d)
← Back to list
9.8
CVE-2026-15748
wpmudev · Forminator Forms – Contact Form, Payment Form & Custom Form Builder

Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration

Description

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

Affected Products

VendorProductVersions
wpmudevForminator Forms – Contact Form, Payment Form & Custom Form Builder0

References

  • https://www.wordfence.com/threat-intel/vulnerabilities/id/263ac05d-f1ca-46e3-a43e-3b45eb8066d4?source=cve
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/fields/upload.php#L552
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/modules/custom-forms/front/front-action.php#L2767
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/modules/custom-forms/front/front-action.php#L738
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/helpers/helper-fields.php#L3425
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/library/abstracts/abstract-class-field.php#L2308
  • https://plugins.trac.wordpress.org/browser/forminator/tags/1.55.1/admin/classes/class-admin-ajax.php#L1196

Related News (3 articles)

Tier D
SecurityWeek10d ago
300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
→ No new info (linked only)
Tier D
Heise Security10d ago
WordPress-Plug-in Forminator Forms: Kritische Lücke erlaubt Codeschmuggel
→ No new info (linked only)
Tier C
VulDB10d ago
CVE-2026-15748 | WPMU DEV Forminator Forms Plugin up to 1.56.1 on WordPress handle_file_upload unrestricted upload
→ No new info (linked only)
CVSS 3.19.8 CRITICAL
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-434
PublishedAug 18, 2026
Last enriched10d ago
Trending Score19
Source articles3
Independent3
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-76581EXPKEV
WPMU DEV Dashboard <= 5.0.1 - Authentication Bypass to Administrator via SSO HMAC Canonicalization Confusion
Trending: 96
HIGHCVE-2026-18324
Forminator Forms <= 1.57.0.1 - Unauthenticated Stored Cross-Site Scripting via Rich-Text Textarea Field
Trending: 26
HIGHCVE-2026-18328
Forminator Forms <= 1.57.0 - Unauthenticated DOM-Based Cross-Site Scripting via 'error_description' Parameter
Trending: 24
HIGHCVE-2026-18323
Forminator Forms <= 1.57.0.2 - Unauthenticated Stored Cross-Site Scripting via Radio Field (Save and Continue Draft)
Trending: 17
MEDIUMCVE-2026-12998
Forminator Forms <= 1.55.0.2 - Insecure Direct Object Reference to Unauthenticated Sensitive Information Disclosure via 'draft' Parameter
Trending: 7

Pin to Dashboard

Verification

State: verified
Confidence: 0%

Vulnerability Timeline

CVE Published
Aug 18, 2026
Discovered by ZDM
Aug 18, 2026