Home › Intelligence › Brief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Unauthenticated RCE in Forminator WordPress Plugin (CVE‑2026‑15748) Threatens 600k Sites

A remote code execution flaw (CVE‑2026‑15748) in the Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious PHP files, potentially compromising any site using the plugin. With a CVSS score of 9.8, the issue underscores the importance of continuous third‑party component monitoring to satisfy SOC 2 vendor‑risk requirements.

LiveThreat™ Intelligence · 📅 August 18, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
thehackernews.com

Critical Unauthenticated RCE in Forminator WordPress Plugin (CVE‑2026‑15748) Threatens 600k Sites

What It Is — A remote‑code‑execution vulnerability in the Forminator Forms WordPress plugin that allows an unauthenticated attacker to upload a malicious PHP file and execute arbitrary code on the host site.

Exploitability — Publicly disclosed with a CVSS 9.8 (Critical). No public exploit code yet, but the unauthenticated upload path makes exploitation trivial.

Affected Products — Forminator Forms plugin for WordPress (all versions prior to the vendor’s forthcoming patch). The plugin reports more than 600,000 active installations.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the need for continuous third‑party component inventory and patch management, a core SOC 2 vendor‑risk control.
  • Failure to remediate promptly can be cited as a control deficiency during a SOC 2 audit, jeopardizing the “Security” and “Availability” principles.
  • Enterprise buyers increasingly demand verifiable evidence that SaaS providers monitor and remediate open‑source and plugin vulnerabilities in real time.

Recommended Actions

  • Update Forminator to the patched version immediately; if a patch is not yet available, temporarily disable the plugin.
  • Conduct a rapid inventory of all WordPress plugins and verify they are up‑to‑date.
  • Integrate automated vulnerability scanning of third‑party components into your CI/CD pipeline.
  • Document remediation steps and retain logs as audit evidence for SOC 2.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your third-party risk controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →