This WordPress Plugin Flaw Lets Hackers Run Code on Your Site

·
Listen to this article~5 min
This WordPress Plugin Flaw Lets Hackers Run Code on Your Site

A critical flaw in Forminator Forms, a WordPress plugin with 600,000+ installs, could let attackers execute code on your site. Rated 9.8 on the CVSS scale, this is one you can't ignore.

If you run a WordPress site with the Forminator Forms plugin, you might want to sit down for this one. A critical security flaw has just been uncovered in this popular plugin, and it's not the kind of bug you can shrug off. We're talking about a vulnerability that could let an attacker completely take over your website without even logging in. ### The Short Version: What's Happening The issue lives in Forminator Forms, a plugin with more than 600,000 active installations. That's a massive attack surface, and the severity score reflects it. The vulnerability, tracked as CVE-2026-15748, carries a CVSS rating of 9.8 out of 10. That's about as serious as it gets in the world of web security. What does that number actually mean for you? In plain terms, it means the flaw is trivially easy to exploit and the potential damage is enormous. An attacker could upload a malicious PHP file to your server and execute arbitrary code. Once they're in, they can do just about anything: steal data, deface your site, inject malware, or use your server as a launching pad for attacks on other sites. ### Who Found This and How Did They Do It? The discovery was made by a security researcher who goes by the online alias "[redacted]." They reported the issue through the proper channels, which is good news for the rest of us. Responsible disclosure means the plugin's developers had a heads-up before the details went public. But here's the thing: knowing about a fix and actually applying it are two different things. ### Why This Flaw Is So Dangerous Let's break down why a 9.8 rating isn't just a number they throw around casually. For a vulnerability to score that high, it usually needs to hit several criteria at once: - No authentication required (attacker doesn't need a login) - Remote exploitation possible (no physical access needed) - High impact (full system compromise is on the table) - Low complexity (no advanced skills required to pull it off) That's a nasty combination. It means a script kiddie with the right exploit code could theoretically take down a site running the vulnerable plugin. You don't need to be a nation-state actor to make this work. ### What Should You Do Right Now? If you're using Forminator, don't panic, but do act. The first step is to check your version and compare it against the latest release. If you're behind, update immediately. It's the simplest and most effective thing you can do. For those managing multiple sites, this is a good reminder to audit your plugin inventory. Old, unused plugins are a common attack vector, and they're easy to forget. If you're not actively using Forminator, deactivate and delete it. Every plugin you remove is one less door into your server. ### A Quick Word on WordPress Security Habits This isn't the first critical flaw in a popular WordPress plugin, and it won't be the last. The ecosystem is vast, and the attack surface grows with every plugin you add. That's not a reason to avoid plugins altogether, but it is a reason to be selective and stay current. Here are a few habits worth adopting: - Enable automatic updates for plugins where possible - Regularly review your plugin list and remove anything you don't use - Use a security plugin that monitors for file changes - Keep backups off-site and test them periodically ### The Bottom Line A 9.8 CVSS score is a five-alarm fire in the security world. If you're running Forminator Forms, treat this with urgency. Update your plugin today, and while you're at it, take a hard look at your overall WordPress hygiene. The tools that make your site powerful also make it vulnerable, and staying safe is a constant process, not a one-time fix. This vulnerability is a reminder that the web is a shared space, and one unpatched site can have ripple effects far beyond its own borders. Do your part, patch your stuff, and keep your digital house in order.