Search

Find merged stories by title or summary.

Vulnerabilities & Patches
Emerging1 src

300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on SecurityWeek .

·SecurityWeek
Read →
Vulnerabilities & Patches
Emerging1 src

Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks

A critical security flaw in the Forminator Forms WordPress plugin could allow unauthenticated attackers to upload malicious PHP files , potentially enabling them to take full control of vulnerable websites. The issue, tracked as CVE-2026-15748, affects Forminator Forms versions 1. 56. 1 and earlier and carries a CVSS severity score of 9. 8. Forminator Forms is a widely used drag-and-drop plugin for building contact, payment, poll, quiz, and file-upload forms. With more than 600,000 active installations, the vulnerability poses a significant risk to WordPress administrators who have not yet applied the available update. WordPress Plugin Vulnerability The flaw was reported through the Wordfence bug bounty program by security researcher daroo, who received a $2,048 reward for the discovery.

·Cyber Security News
Read →
Vulnerabilities & Patches
Emerging1 src

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites. The vulnerability, tracked as CVE-2026-15748, is rated 9. 8 out of 10. 0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias "

·The Hacker News
Read →

You've reached the end of current stories for this search.