Critical WordPress Plugin Flaw Puts 600,000+ Sites at Risk of Takeover
A serious security flaw has been discovered in Forminator Forms, a widely used WordPress plugin installed on more than 600,000 websites. The vulnerability, tracked as CVE-2026-15748, has received a near-maximum severity score of 9.8 out of 10, indicating it is both easy to exploit and highly damaging if left unpatched.
The issue allows attackers to upload malicious PHP files to a vulnerable site without needing to log in or authenticate in any way. If exploited, this could let cybercriminals run their own code on the affected server, potentially giving them full control of the website, access to customer data, or a foothold to launch further attacks.
Many Australian small businesses use WordPress for their websites and rely on plugins like Forminator to manage contact forms, quotes, and customer inquiries. Because the plugin is so widely used, this vulnerability could affect a large number of sites if not addressed quickly. Businesses should check whether they use Forminator Forms and apply any available security update as soon as possible.