Close Menu
NCIJ Network NCIJ Network
    What's Hot

    SEC Proposes New Crypto Rules in Absence of CLARITY Act

    August 18, 2026

    Shrews’ noses grow in winter as their brains shrink

    August 18, 2026

    Elders, conservationists race to record fading sacred ties to Philippines’ endemic birds

    August 18, 2026
    Facebook X (Twitter) Instagram
    Trending
    • SEC Proposes New Crypto Rules in Absence of CLARITY Act
    • Shrews’ noses grow in winter as their brains shrink
    • Elders, conservationists race to record fading sacred ties to Philippines’ endemic birds
    • Trump says no Iran talks planned, insists Strait of Hormuz remains open
    • Andy Burnham received £345,000 of donations ahead of becoming PM
    • OpenAI says it will expand monitoring of model testing after hacking incident
    • I tested GNOME’s glassy new look – and it’s simply spectacular
    • 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw
    • About
      • Our Team
      • Editorial Policy
      • Editorial Independence
      • International Support
    • Trust & Standards
      • AI Usage Policy
      • Conflict of Interest Policy
      • Corrections Policy
      • Ethics Policy
      • Fact-Checking Policy
      • Source Protection
    • Get Involved
      • Guide for Sources
      • Support Independent Journalism
    • Legal
      • Cookie Policy
      • Privacy Policy
      • Terms of Use
    Facebook X (Twitter) Instagram
    NCIJ Network NCIJ Network
    Tuesday, August 18
    • Home
    • World
    • Ai
    • Business
    • Politics
    • Health
    • Crypto
    • Science
    • Technology
    • Cybersecurity
    • Defense & Security
    • Economy
    • Energy
    • Europe
    • More
      • Fact Check
      • Investigations
      • Opinion & Analysis
      • Environment
    NCIJ Network NCIJ Network
    Home»Cybersecurity

    300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw

    NCIJ NETWNCIJ NETWORKBy NCIJ NETWNCIJ NETWORKAugust 18, 2026 Cybersecurity No Comments2 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    A critical vulnerability in the Forminator Forms plugin for WordPress potentially exposes thousands of websites to remote code execution (RCE), WordPress security firm Defiant warns.

    Tracked as CVE-2026-15748 (CVSS score of 9.8), the bug is described as an arbitrary file upload via the handle_file_upload function of the popular form builder plugin.

    Insufficient file type validation in the affected function allows unauthenticated attackers to upload executable files, leading to code execution.

    According to Defiant, the issue is a combination of several weaknesses that enable attackers to forge records using the Select field on a form, take control of the field configuration passed to the upload function, and bypass the plugin’s blocklist of dangerous file types.

    “This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value,” Defiant explains.

    In default configurations, files land in a protected directory that prevents PHP execution. However, if a Custom File Upload Storage root has been configured, the protection is not applied to it, and the attacker-supplied PHP code is executed when the uploaded file is requested directly.

    Advertisement. Scroll to continue reading.

    “As with all arbitrary file upload vulnerabilities, this can lead to complete site compromise through the use of webshells and other techniques,” Defiant notes.

    The vulnerability impacts all Forminator Forms versions up to 1.56.1 and was patched in version 1.56.2, released on July 31.

    The plugin has over 600,000 installations and, based on WordPress data, half of them run a vulnerable version. This means that over 300,000 websites are potentially exposed to attacks. Currently, there are no reports of the bug’s in-the-wild exploitation.

    Related: GitLab Patches Critical Code Injection Vulnerability

    Related: Dozens of WebKit Vulnerabilities Patched With Fresh macOS, iOS Security Updates

    Related: Recent macOS Screen Sharing Vulnerability Exploited in Attacks

    Related: Critical SAP Commerce Cloud Vulnerability Exploited 3 Days After Disclosure

    due exposed Flaw form hacking Plugin Potentially sites WordPress
    NCIJ NETWNCIJ NETWORK
    • Website

    Keep Reading

    OpenAI says it will expand monitoring of model testing after hacking incident

    Fortinet Acquires AI Security Company Virtue AI

    Xpander Raises $7.5 Million for AI Management and Governance

    Microsoft Copilot Personal Flaws Could Let One Click Exfiltrate Data From Connected Apps

    AI-Driven Vulnerability Surge Breaks the Traditional Patching Model

    CISO Conversations: Nico Waisman – From Self-Taught Hacker to AI-Driven Offensive Security at XBOW

    Add A Comment
    Leave A Reply Cancel Reply

    Editors Picks

    SEC Proposes New Crypto Rules in Absence of CLARITY Act

    August 18, 2026

    Shrews’ noses grow in winter as their brains shrink

    August 18, 2026

    Elders, conservationists race to record fading sacred ties to Philippines’ endemic birds

    August 18, 2026

    Trump says no Iran talks planned, insists Strait of Hormuz remains open

    August 18, 2026
    Latest Posts

    Tether’s XAUT Gains Shariah Certification for Islamic Finance

    July 27, 2026

    Nvidia and Tech Giants Launch AI Security Alliance

    July 27, 2026

    Perplexity Releases pplx, a Single-Binary CLI That Puts Its Search API in the Terminal for Coding Agents

    July 27, 2026

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    NCIJ Network is an independent digital news platform delivering trusted investigative journalism, European and global news, in-depth analysis, and fact-based reporting with accuracy, transparency, and integrity.

    Facebook X (Twitter) Instagram Pinterest YouTube

    SEC Proposes New Crypto Rules in Absence of CLARITY Act

    August 18, 2026

    Shrews’ noses grow in winter as their brains shrink

    August 18, 2026

    Elders, conservationists race to record fading sacred ties to Philippines’ endemic birds

    August 18, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.