300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. The post 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw appeared first on SecurityWeek.
A critical vulnerability in the Forminator Forms plugin for WordPress potentially exposes thousands of websites to remote code execution (RCE), WordPress security firm Defiant warns.
Tracked as CVE-2026-15748 (CVSS score of 9.8), the bug is described as an arbitrary file upload via the handle_file_upload function of the popular form builder plugin.
Insufficient file type validation in the affected function allows unauthenticated attackers to upload executable files, leading to code execution.
Related breach coverage
- Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites2026-09-05
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions. The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek.
- Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability2026-09-03
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek.
- GitLab Vulnerability Exploited One Day After Disclosure2026-09-11
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.
- Hackers Start Exploiting Critical Langflow Vulnerability2026-09-01
Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely. The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek.