{"id":2384,"date":"2026-08-17T20:57:55","date_gmt":"2026-08-17T20:57:55","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2384"},"modified":"2026-08-17T20:57:55","modified_gmt":"2026-08-17T20:57:55","slug":"forminator-wordpress-flaw-can-enable-unauthenticated-rce-via-malicious-php-uploads","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2384","title":{"rendered":"Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Aug 17, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Website Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEg5Jfag1_E06odK7mkATjCOSPdD_fHy2kcYYHfi9fDNTsk0CRkV2yJD0Uz4MV82XjbMR5QNyK3Akw5Ysf0N7fDQ3DwApNb5Tf9R4axktScKF3UZlMVtrY3ulTzrYjFviMA8HmIUCBZhxmR59TtnJ7xf-B_iJtl3SWiBZAFbOfhUoldNdZX0sOStx6ULNMSZ\/s1700-e365\/wordpress-flaw.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited to achieve arbitrary code execution on susceptible sites.<\/p>\n<p>The vulnerability, tracked as <strong>CVE-2026-15748<\/strong>, is rated 9.8 out of 10.0 on the CVSS scoring system. It was discovered and reported by a security researcher who goes by the online alias \u00abdaroo.\u00bb<\/p>\n<p>\u00abThis vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site compromise,\u00bb Wordfence <a href=\"https:\/\/www.wordfence.com\/blog\/2026\/08\/600000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-forminator-forms-wordpress-plugin\/\" target=\"_blank\">said<\/a> in a report published today.<\/p>\n<p>That said, a key prerequisite for successful exploitation is that the sites must have a form containing both a File Upload field and a Select field. The vulnerability impacts all versions of the plugin before and including 1.56.1. It has been addressed in version 1.56.2 released on July 31, 2026.<\/p>\n<p>Per the WordPress security company, the flaw is a case of arbitrary file upload that resides in the \u00abhandle_file_upload()\u00bb function, stemming from a lack of sufficient file type validation in user-supplied input.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/zero-trust-claude-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj8iAp2j8rqTq6aptj6yiYHC-B73UxnWI2NQMt0azp6OVLq9JkO8cpYokLWa8t_IKqrHKPsaM5D_lQ9Ip7kZTi3at4oYfzN1m1b_T4b6MuzBWtmlhdLcQ0nZHicD94rliREFDRewsKBQCTYrAAVNzYKj84_0EZskDUxvkc972s9fYAqcQGEQjVZTc0cr7TB\/s728-e100\/ThreatLocker-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>As a result, an unauthenticated attacker can exploit the loophole to upload any file, including a specially crafted PHP file, to a vulnerable site by submitting a form and achieving remote code execution. Armed with this capability, the attacker can seize control of the site.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>\u00abThis is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value,\u00bb Wordfence said.<\/p>\n<p>Another aspect worth noting here is that, in the default configuration, files are uploaded to a directory protected by an .htaccess file that prevents PHP execution. But if a site administrator has configured a Custom File Upload Storage root, it may not have the same safeguard as the file is created \u00abonly when it is first needed, during a frontend request where the WordPress helper responsible for writing the .htaccess file is not loaded.\u00bb<\/p>\n<p>As a result, requesting the uploaded file is enough to cause the web server to execute the attacker-controlled PHP code.<\/p>\n<h3>Auth Bypass Flaw in User Profile Builder Plugin<\/h3>\n<p>The disclosure comes days after Wordfence also highlighted another critical authentication bypass bug in User Profile Builder, which has more than 40,000 active WordPress installations, that could allow unauthenticated attackers to log in as the user with ID 1 (typically the site administrator) and take over the site.<\/p>\n<p>The vulnerability, tracked as <strong>CVE-2026-15826<\/strong> (CVSS score: 9.8), was patched on July 16, 2026, with the release of version 3.16.5. All prior versions are affected by the issue, but it is only exploitable on sites where the plugin&#8217;s Automatically Log In setting is enabled.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/corelight-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjuvAqH13TTYyJD3aI-pJcYl54BoxQWMHc2aFwW2HbYUa5IKCjvHlzpzkFwXLTuV8aytky8kqLBgkoOtC8VQM5CGR0N5BXBl8RSXl-PYx_vIPbiLywiqXIvTPmm18cdEm_C0heVB-3U8zfG7K27RCAurtJ7OvxEyfQ0sVV_RRx1N4ZMWkqKgEBmkcDgjD6I\/s728-e100\/code-d.png\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abThis is due to the wppb_log_in_user() function calling absint() on the return value of wp_insert_user() before performing an is_wp_error() check \u2014 when a registration is submitted with a 61\u201370 character username, WordPress core rejects it with a WP_Error object, but absint() coerces that object to the integer 1 before the error check can short-circuit execution, causing the plugin to bind and return a transient-backed autologin nonce tied to user ID 1,\u00bb Wordfence <a href=\"https:\/\/www.wordfence.com\/blog\/2026\/08\/40000-wordpress-sites-affected-by-authentication-bypass-vulnerability-in-user-profile-builder-wordpress-plugin\/\" target=\"_blank\">said<\/a>.<\/p>\n<p>\u00abThis makes it possible for unauthenticated attackers to log in as the site&#8217;s Administrator account (user ID 1), resulting in full administrative takeover of the site.\u00bb<\/p>\n<p>Site owners who have either of the two plugins are advised to apply the updates as soon as possible and ensure their installations are up-to-date.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Aug 17, 2026Vulnerability \/ Website Security A critical security flaw has been disclosed in Forminator Forms, a WordPress plugin with more than 600,000 active installations, that could be exploited&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2385,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[369,70,3033,33,1067,316,725,795,1927],"class_list":["post-2384","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-enable","tag-flaw","tag-forminator","tag-malicious","tag-php","tag-rce","tag-unauthenticated","tag-uploads","tag-wordpress"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2384","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2384"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2384\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2385"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2384"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2384"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2384"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}