Critical Unauthenticated RCE in Forminator WordPress Plugin (CVE‑2026‑15748) Threatens 600k Sites
What It Is — A remote‑code‑execution vulnerability in the Forminator Forms WordPress plugin that allows an unauthenticated attacker to upload a malicious PHP file and execute arbitrary code on the host site.
Exploitability — Publicly disclosed with a CVSS 9.8 (Critical). No public exploit code yet, but the unauthenticated upload path makes exploitation trivial.
Affected Products — Forminator Forms plugin for WordPress (all versions prior to the vendor’s forthcoming patch). The plugin reports more than 600,000 active installations.
Why It Matters for Compliance & Audit Readiness
- Demonstrates the need for continuous third‑party component inventory and patch management, a core SOC 2 vendor‑risk control.
- Failure to remediate promptly can be cited as a control deficiency during a SOC 2 audit, jeopardizing the “Security” and “Availability” principles.
- Enterprise buyers increasingly demand verifiable evidence that SaaS providers monitor and remediate open‑source and plugin vulnerabilities in real time.
Recommended Actions
- Update Forminator to the patched version immediately; if a patch is not yet available, temporarily disable the plugin.
- Conduct a rapid inventory of all WordPress plugins and verify they are up‑to‑date.
- Integrate automated vulnerability scanning of third‑party components into your CI/CD pipeline.
- Document remediation steps and retain logs as audit evidence for SOC 2.
Source: The Hacker News