What is CVE-2026-15748?
A critical vulnerability (CVE-2026-15748) in the Forminator WordPress plugin allows unauthenticated remote code execution (RCE) via malicious PHP uploads. This flaw impacts over 600,000 active installations and has a CVSS score of 9.8. Immediate plugin update to the latest patched version is strongly recommended.
Azərbaycanca: Forminator WordPress plaqinində kritik boşluq (CVE-2026-15748) autentifikasiya olunmadan uzaqdan kod icrasına (Unauthenticated RCE) imkan verir. 600 mindən çox aktiv quraşdırmaya təsir edən bu qüsur, zərərli PHP fayllarının yüklənməsi yolu ilə ixtiyari kod icrasına səbəb ola bilər. Plaqini dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-434
FAQ2
How critical is the CVE-2026-15748 vulnerability in the Forminator plugin?
This vulnerability is rated critical with a CVSS score of 9.8, as it allows unauthenticated remote code execution (RCE).
What should be done to protect against CVE-2026-15748?
To protect against this flaw, which impacts over 600,000 active installations, it is strongly recommended to immediately update the Forminator plugin to the latest patched version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.