Skip to main content

Tag: cve 2026 15748

1 article

Laptop screen showing WordPress backend with file upload, in a cluttered office with city view.

WordPress Plugin Flaw Enables Unauthenticated Remote Code Execution

A critical vulnerability in the Forminator Forms WordPress plugin can let hackers upload malicious PHP files to your site, allowing them to take control and wreak havoc - all without needing a login. This flaw, tracked as CVE-2026-15748, has a near-perfect severity score of 9.8, making it a high-priority threat.

Analyst 207