Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 18 Aug 2026 06:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wordpress
Wordpress wordpress Wpmudev Wpmudev forminator Forms – Contact Form, Payment Form & Custom Form Builder |
|
| Vendors & Products |
Wordpress
Wordpress wordpress Wpmudev Wpmudev forminator Forms – Contact Form, Payment Form & Custom Form Builder |
Tue, 18 Aug 2026 05:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. | |
| Title | Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration | |
| Weaknesses | CWE-434 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-08-18T05:31:20.458Z
Reserved: 2026-07-14T15:09:34.890Z
Link: CVE-2026-15748
No data.
Status : Received
Published: 2026-08-18T06:16:40.670
Modified: 2026-08-18T06:16:40.670
Link: CVE-2026-15748
No data.
OpenCVE Enrichment
Updated: 2026-08-18T06:30:08Z