Security News

WordPress Form Plugin Flaw Puts 300,000 Sites at Risk of Takeover

Security Week · 18 Aug 2026
Key Takeaway If your business website runs WordPress, check your form plugins now and update immediately to patch known vulnerabilities before attackers exploit them.

A serious security flaw has been discovered in a widely used WordPress form plugin, potentially putting 300,000 websites at risk of being hacked. Tracked as CVE-2026-15748, the vulnerability allows attackers to upload executable files to a website without needing any login credentials, a type of flaw known as an arbitrary file upload bug.

This kind of vulnerability is particularly dangerous because it can let attackers plant malicious code directly onto a website, potentially giving them full control of the site. From there, criminals could deface the site, steal customer data, redirect visitors to scam pages, or use the compromised site as a launchpad for further attacks.

For small and medium businesses running WordPress sites, especially those using contact or lead-generation forms, this is a timely reminder that plugins are a common entry point for attackers. Website owners should check whether they are using the affected plugin and apply any available security update as soon as possible.

Summarised by CISO AI from Security Week. We link back to every original so you can read it yourself.