Update Forminator Forms to the latest patched version when available. Implement file upload restrictions and validation. Use web application firewall rules to block suspicious file uploads. Monitor official Forminator security advisories for patch release. Apply WordPress security best practices including regular updates and restricted file permissions.
Quick answers
What is CVE-2026-15748?
Update Forminator Forms to the latest patched version when available. Implement file upload restrictions and validation. Use web application firewall rules to block suspicious file uploads. Monitor official Forminator security advisories for patch release. Apply WordPress security best practices including regular updates and restricted file permissions.
How severe is CVE-2026-15748?
critical, CVSS 9.8
Is CVE-2026-15748 known to be exploited?
It is not marked known-exploited in this record.
How should CVE-2026-15748 be mitigated?
Update Forminator Forms to the latest patched version when available. Implement file upload restrictions and validation. Use web application firewall rules to block suspicious file uploads. Monitor official Forminator security advisories for patch release. Apply WordPress security best practices including regular updates and restricted file permissions.
CVSS
9.8
Vendor
Forminator
Published
Sep 30, 2026 · 08:05
Patch
Unknown / not confirmed
Affected products
Forminator Forms
Mitigation
Update Forminator Forms to the latest patched version when available. Implement file upload restrictions and validation. Use web application firewall rules to block suspicious file uploads. Monitor official Forminator security advisories for patch release. Apply WordPress security best practices including regular updates and restricted file permissions.
A critical security vulnerability in the Forminator Forms WordPress plugin, tracked as CVE-2026-15748, has been disclosed with a CVSS score of 9.8. The flaw enables unauthenticated remote code execution through malicious PHP file uploads, affecting over 600,000 active installations. The vulnerability was reported by a security researcher and details are pending official patch release and exploitation confirmation.