Observed Signal · Aug 19, 2026 · Technical Release · Source: DEV Community · Impact: 3/5 · Sentiment: Negative

Forminator Forms CVE-2026-15748: Unauthenticated RCE via Select Fields

Executive Signal Summary

A high-severity vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin (versions 1.56.1 and earlier) allows an unauthenticated attacker to inject forged upload settings via a Select field, enabling arbitrary file upload and potential remote code execution if the upload storage permits PHP execution. Wordfence reported the issue and estimated roughly 600,000 WordPress sites could be affected; the vulnerability is fixed in Forminator version 1.56.2. Exploitation requires a public form containing both a File Upload and a Select field and relies on bypassing extension blocklists (example: the string "ph(p)|text/x-php"). Defenders are advised to update the plugin, disable script execution in upload locations, and hunt for abnormal POST payloads and newly created PHP files in upload directories.

Polaris7 AgentPolaris7 Strategic Assessment
High Confidence

Widespread WordPress usage for business and marketing sites means an unauthenticated RCE in a popular plugin (fixed in 1.56.2) risks mass site compromise, data theft, and abuse of marketing infrastructure; requires timely patching and detection.

SIGNAL RADAR

Track Google Signals & Market Shifts in Real-Time

Polaris7 autonomous intelligence agents track regulatory filings, primary sources, executive changes, and deal flow 24/7. Create your free Explorer workspace to monitor these entities.

Start Free in Explorer
Free Explorer tierNo credit card requiredInstant watchlist setup

Key Takeaways & Evidence Grounding

  • CVE-2026-15748 affects Forminator Forms versions 1.56.1 and earlier and is fixed in 1.56.2.
  • Wordfence Intelligence reported the issue and estimated ~600,000 WordPress sites could be affected.
  • The flaw lets an unauthenticated attacker inject fake upload settings into a Select field to create file uploads; RCE occurs if upload storage allows PHP execution.
  • Exploitation uses techniques that bypass exact-match extension blocklists (example bypass string: ph(p)|text/x-php).

Connected Companies & Entities

2 Entities mapped

“Gemini 3.5 Flash ... is generally available (GA) ... As our most intelligent Flash model, it delivers sustained frontier performance......”

“The article is hosted on dev.to (author page and post URL shown at top of the content)....”

Primary Source Grounding & Direct Attribution
Direct Origin Attribution
Primary Reporting: DEV Community•Published: Aug 19, 2026
Original Coverage Title: “Forminator Forms (CVE-2026-15748): Unauthenticated RCE via Forged Upload Settings in Select Fields”

Related Market Signals & Shifts

Recent verified developments and strategic activity across this market segment.

Security / VulnerabilityJul 20, 2026

Hackers Exploit Recently Patched WordPress Flaws

Security researchers and multiple cybersecurity firms warn that attackers are actively exploiting two recently patched critical WordPress vulnerabilities (affecting versions 6.9.0–6.9.4 and 7.0.0–7.0.1). WordPress pushed immediate and, where possible, forced updates after the fixes were released. Firms including Patchstack, Hexastrike, and WatchTowr reported in-the-wild exploitation. Researcher Daniel Card sampled ~4,200 sites and estimates under 15% remain vulnerable, which could extrapolate to roughly 90 million at-risk WordPress sites. The exploit chain includes a vulnerability dubbed WP2Shell, reported by Adam Kues of Searchlight Cyber. Cloudflare and web application firewalls have helped block some attacks while many sites remain exposed.

Read assessment
Supply chain compromise / CMS securityAug 11, 2026

BdThemes Supply-Chain XSS Leads to Web Shells

Wordfence Threat Intelligence reported a critical supply-chain compromise in the BdThemes ecosystem where attackers wrote malicious JSON to the vendor's static storage. A DOM XSS (unescaped display_id in the Biggopti JSON) executed inside logged-in WordPress administrator browsers, causing external scripts (w2.js / x.js) to run. The payloads used administrator sessions to create rogue admin accounts, upload a fake plugin, deploy a web shell (emer-run.php), install MU-plugin persistence, and hide created accounts while beaconing results to a C2. Active attacks were observed on August 7, 2026 and the vendor JSON returned to clean on August 8. Affected plugins include Element Pack, Prime Slider, Pixel Gallery, Ultimate Post Kit, Ultimate Store Kit, Live Copy Paste, Smart Admin Assistant.

Read assessment
Content Management System (CMS) SecurityApr 15, 2026

WordPress Plugins Infected with Backdoor

A security researcher, Austin Ginder, discovered that more than 30 WordPress plugins were modified to include a backdoor allowing attackers to inject malicious content into websites. The affected plugins — originally developed by an Indian team called WP Online Support and later sold in early 2025 to an anonymous buyer using the nickname “Kris,” who renamed the collection Essential Plugin — remained dormant until the backdoor was activated in early April 2026. Injected payloads reportedly loaded spam links, redirects, fake pages and crypto-related links from a remote server, and the injections were cloaked so only Google’s crawler could see them. Essential Plugin says the infected addons had over 400,000 installs; the extensions have since been disabled in the WordPress store. Ginder published a patch and a removal recommendation for site operators.

Read assessment

Track Real-Time Market Signals & Shifts

Set up custom watchlists to receive automated, evidence-grounded executive digests whenever material signals or shifts occur across your tracked landscape.