A critical flaw in Forminator Forms, a WordPress plugin with 600,000+ installs, could allow unauthenticated attackers to execute arbitrary code. Update now to protect your site.
If you run a WordPress site, you know the drill: keep your plugins updated, hope nothing breaks, and pray you don't wake up to a hacked dashboard. But a newly disclosed vulnerability in Forminator Forms, a plugin used by over 600,000 sites, is the kind of thing that should make you sit up and pay attention.
This isn't a minor issue. We're talking about a critical flaw that could allow an attacker to execute arbitrary code on your server without even logging in. That's the worst-case scenario for any site owner, and it's exactly why this needs your attention right now.
### What's Actually Going On?
The vulnerability, tracked as CVE-2026-15748, carries a CVSS score of 9.8 out of 10. That's about as severe as it gets. The flaw sits in how Forminator handles file uploads, and it can be exploited to upload a malicious PHP file to your server. Once that file is in place, the attacker can run whatever code they want, which basically means they own your site.
What makes this especially dangerous is the "unauthenticated" part. The attacker doesn't need a username or password. They don't need to be a subscriber or an admin. They just need to find a site running a vulnerable version of the plugin and send a specially crafted request. That's it.
### Who Found It and What Happens Next?
The bug was discovered and reported by a security researcher who goes by the online alias "Neznajka." They did the responsible thing and reported it privately, which gave the Forminator team time to build a fix before the details went public. That's how it should work, but it also means you need to act fast if you haven't updated yet.
Here's the thing about critical vulnerabilities like this: once the details are out, attackers start scanning for vulnerable sites almost immediately. It's not a matter of if they'll target you, it's a matter of when. The window between disclosure and exploitation is often measured in hours, not days.
### What You Should Do Right Now
- **Update Forminator immediately.** Check your WordPress admin panel and install the latest version of the plugin. If there's an update available, don't put it off.
- **Check your site for signs of compromise.** Look for unfamiliar files in your uploads directory, especially PHP files. If you see anything suspicious, don't open it, and consider reaching out to a security professional.
- **Review your user accounts.** Make sure there aren't any new admin accounts you didn't create. Attackers often add backdoor accounts after they gain access.
- **Enable automatic updates for plugins.** It's not a perfect solution, but it closes the gap between a patch being released and you actually installing it.
- **Back up your site.** If things go sideways, you'll want a clean backup to restore from. Make sure your backup is stored somewhere separate from your hosting account.
### Why This Matters Beyond the Patch
This vulnerability is a reminder that the plugins you rely on are built by humans, and humans make mistakes. The good news is that the Forminator team responded quickly, but the bad news is that this won't be the last critical flaw we see in popular WordPress plugins.
If you're running a business on WordPress, consider this a wake-up call to take your security posture seriously. That means keeping everything updated, using strong passwords, and maybe investing in a web application firewall. It's a lot easier to prevent an attack than to clean up after one.
### The Bottom Line
Don't wait. Update Forminator today, check your site for anything unusual, and make sure you have a solid backup strategy in place. This vulnerability is serious, but it's also a manageable problem if you act now. The worst thing you can do is assume it won't happen to you, because with 600,000 installations, the odds aren't in your favor.