WordPress Form Plugin Flaw Puts 300,000 Sites at Risk of Takeover
A serious security flaw has been discovered in a widely used WordPress form plugin, potentially putting 300,000 websites at risk of being hacked. Tracked as CVE-2026-15748, the vulnerability allows attackers to upload executable files to a website without needing any login credentials, a type of flaw known as an arbitrary file upload bug.
This kind of vulnerability is particularly dangerous because it can let attackers plant malicious code directly onto a website, potentially giving them full control of the site. From there, criminals could deface the site, steal customer data, redirect visitors to scam pages, or use the compromised site as a launchpad for further attacks.
For small and medium businesses running WordPress sites, especially those using contact or lead-generation forms, this is a timely reminder that plugins are a common entry point for attackers. Website owners should check whether they are using the affected plugin and apply any available security update as soon as possible.