600,000 WordPress sites run this form plugin. one bug turns a dropdown into a hacker's backdoor

A file-upload field and a dropdown, sitting on the same form, are all it takes for an unauthenticated attacker to plant PHP code on your site. The…

Aliteq
Priya Nair · Software & Systems Editor

CVE-2026-15748 is a CVSS 9.8 unauthenticated arbitrary file upload flaw in Forminator Forms, a WordPress plugin with 600,000+ active installs.

It only affects forms combining a File Upload field with a Select (dropdown) field — an extremely common combination.

WPMU DEV fixed it in version 1.56.2, released July 31, 2026 — before Wordfence publicly disclosed the bug on August 17.

Despite the fix existing for over two weeks before disclosure, SecurityWeek estimated 300,000+ sites were still running vulnerable versions when the advisory went public.

Exploitation requires no login and no admin interaction — the attacker just submits the form like anyone else.

My take

Silent security patches are arguably worse than no patch at all, because they create a false sense that 'update when convenient' is a safe policy. It isn't, and this isn't the first time it's bitten…

Aliteq

Read the full story

600,000 WordPress sites run this form plugin. one bug turns a dropdown into a hacker's backdoor

Read the full story on Aliteq