Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com
← Back to Vulnerability Briefs

Critical Security Flaw in Popular WordPress Form Plugin

A serious security weakness has been found in the Forminator Forms plugin for WordPress, which could let attackers upload harmful files and take control of your website without needing to log in. This matters because many small businesses use WordPress and this plugin for their websites.

18 August 2026

Reference: CVE-2026-15748

1. What is being reported?

The Forminator Forms plugin, used to create forms on WordPress websites, has a flaw that allows attackers to upload dangerous files by bypassing the plugin’s file checks. This can let them run malicious code on your website remotely.

2. What this means in plain English

If your website uses this plugin and is not updated, attackers could potentially take over your site, steal data, or disrupt your online services. This risk is serious because it can happen without any login or special access.

3. Could this affect a small business?

Small businesses or organisations using WordPress with the Forminator Forms plugin version 1.56.1 or earlier could be affected. If you do not use WordPress or this plugin, this vulnerability does not apply to you.

4. What to do now

  • Check if your website uses the Forminator Forms plugin and note its version.
  • Ask your website manager or IT provider to update the plugin to the latest safe version immediately.
  • If you cannot update right away, consider temporarily disabling the plugin to reduce risk.
  • Monitor your website for unusual activity and report any concerns to your IT provider.

5. Ask your IT provider

Can you confirm if our WordPress site uses the Forminator Forms plugin and ensure it is updated to a secure version to prevent unauthorised file uploads?

6. Bottom line

Keep your WordPress plugins up to date to protect your website from serious security threats.

Information based on CISA KEV, NVD, and reputable security news reporting.

Back to Vulnerability Briefs