CVE-2026-57815: WordPress Forminator plugin <= 1.55.0.2 - Arbitrary File Download vulnerability
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in WPMU DEV - Your All-in-One WordPress Platform Forminator forminator allows Path Traversal.This issue affects Forminator: from n/a through <= 1.55.0.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WPMU DEV - Forminator (WordPress plugin)to a version that resolves this vulnerability.Fixed in 1.55.0.2
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57815?
CVE-2026-57815 has a severity score of 7.5, which is classified as high.
How do I fix CVE-2026-57815?
To address CVE-2026-57815, update the WordPress Forminator plugin to the latest version beyond 1.55.0.2.
What type of vulnerability is CVE-2026-57815?
CVE-2026-57815 is classified as a Path Traversal vulnerability, allowing arbitrary file downloads.
Which version of Forminator is affected by CVE-2026-57815?
CVE-2026-57815 affects Forminator versions from n/a up to and including 1.55.0.2.
What impact does CVE-2026-57815 have on my website?
CVE-2026-57815 can potentially allow unauthorized users to download arbitrary files from your server.