CVE · Critical

CVE-2026-15748 — Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.56.2

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-15748 Forminator Forms – Contact Form, Payment Form & Custom Form Builder [forminator] < 1.56.2 Unrestricted Upload of File with Dangerous Type Critical 9.8 < 1.56.2 1.56.2 2026-08-18

CVE-2026-15748

The Forminator Forms plugin for WordPress has a vulnerability that allows attackers to upload any type of file, including executable files, without authentication. This is due to a weakness in the plugin's file type validation, which can be bypassed by using alternative MIME types. As a result, attackers can upload malicious files that can be executed remotely, potentially leading to code execution.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.