CVE-2026-15748: Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration
The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handlefileupload function. This is due to insufficient file type validation in handlefileupload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.
Affected Software
Event History
Frequently Asked Questions
Does an attacker need a WordPress account or victim interaction to exploit this?
No. The CVSS vector indicates network-based exploitation with no privileges required and no user interaction required, and the vulnerable submission handler is public.
What is the potential impact of a successful exploit?
The CVSS metrics rate confidentiality, integrity, and availability impact as High. The upload of potentially executable files can make remote code execution possible.