300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

https://www.securityweek.com/wp-content/uploads/2023/01/Cybersecurity_News-SecurityWeek.jpg

A critical vulnerability in the Forminator Forms plugin for WordPress potentially exposes thousands of websites to remote code execution (RCE), WordPress security firm Defiant warns.

Tracked as CVE-2026-15748 (CVSS score of 9.8), the bug is described as an arbitrary file upload via the handle_file_upload function of the popular form builder plugin.

Insufficient file type validation in the affected function allows unauthenticated attackers to upload executable files, leading to code execution.

According to Defiant, the issue is a combination of several weaknesses that enable attackers to forge records using the Select field on a form, take control of the field configuration passed to the upload function, and bypass the plugin’s blocklist of dangerous file types.

“This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field...

Copyright of this story solely belongs to securityweek.com. To see the full text click HERE