HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical Unauthenticated RCE in Forminator WordPress Plugin (CVE‑2026‑15748) Threatens 600k Sites

A remote code execution flaw (CVE‑2026‑15748) in the Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious PHP files, potentially compromising any site using the plugin. With a CVSS score of 9.8, the issue underscores the importance of continuous third‑party component monitoring to satisfy SOC 2 vendor‑risk requirements.

LiveThreat™ Intelligence · 📅 August 18, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

Critical Unauthenticated RCE in Forminator WordPress Plugin (CVE‑2026‑15748) Threatens 600k Sites

What It Is — A remote‑code‑execution vulnerability in the Forminator Forms WordPress plugin that allows an unauthenticated attacker to upload a malicious PHP file and execute arbitrary code on the host site.

Exploitability — Publicly disclosed with a CVSS 9.8 (Critical). No public exploit code yet, but the unauthenticated upload path makes exploitation trivial.

Affected Products — Forminator Forms plugin for WordPress (all versions prior to the vendor’s forthcoming patch). The plugin reports more than 600,000 active installations.

Why It Matters for Compliance & Audit Readiness

  • Demonstrates the need for continuous third‑party component inventory and patch management, a core SOC 2 vendor‑risk control.
  • Failure to remediate promptly can be cited as a control deficiency during a SOC 2 audit, jeopardizing the “Security” and “Availability” principles.
  • Enterprise buyers increasingly demand verifiable evidence that SaaS providers monitor and remediate open‑source and plugin vulnerabilities in real time.

Recommended Actions

  • Update Forminator to the patched version immediately; if a patch is not yet available, temporarily disable the plugin.
  • Conduct a rapid inventory of all WordPress plugins and verify they are up‑to‑date.
  • Integrate automated vulnerability scanning of third‑party components into your CI/CD pipeline.
  • Document remediation steps and retain logs as audit evidence for SOC 2.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Vendor Risk Hub

This is the scenario continuous vendor monitoring is built to catch.

When a vendor is compromised, your SOC 2 vendor-management controls are what produce the audit trail showing you knew, assessed, and acted. The Verisq AI Trust Operations platform tracks that continuously.

Explore the Verisq AI Trust Operations platform →