2026-08-19HIGHThe blocklist matches MIME keys exactly, so a pipe-alternative key walks a PHP file past it
WPMU DEV Forminator Forms (WordPress, 600,000+ installs), unauthenticated arbitrary file upload to remote code execution in handle_file_upload: the dangerous-extension blocklist matches MIME-type keys exactly and is bypassed by a pipe-alternative key, while a forged Select-field value overrides the upload field's own type configuration. CVSS 9.8, Wordfence as CNA. Exploitable only on forms carrying both a File Upload and a Select field. Fixed in 1.56.2 (2026-07-31); root-cause write-up published 2026-08-17, relayed by NCSC-CH 2026-08-18. No exploitation reported.
cve · CVE-2026-15748
Coverage
1
first 2026-08-19 → last 2026-08-19
Latest activity
2026-08-19
The blocklist matches MIME keys exactly, so a pipe-alternative key walks a PHP file past it
Peak priority
high
1 high
Targets
public-sector
sectors: public-sector, education, technology · regions: europe, switzerland
Sources cited
3
3 hosts
Action items (2)
Do-now tasks recorded on the entries about CVE-2026-15748, newest first. Check the date before acting on an older one.
- Inventory WordPress sites running Forminator Forms, update any at or below 1.56.1 to 1.56.2 or later, and for sites that were exposed since 2026-07-31 check whether any form combines a File Upload field with a Select field, that pairing is the precondition and tells you which sites were actually reachable.2026-08-19CVE-2026-15748
- On any Forminator site configured with a Custom File Upload Storage root, verify that directory carries the .htaccess file blocking PHP execution; Wordfence states the protection can be missing there even though the default upload path has it.2026-08-19CVE-2026-15748
Defender insights
What each entry about CVE-2026-15748 tells a defender to do, newest first.
Triage
Story timeline
Hunting pivots
Affected products
ATT&CK techniques (2 across 2 tactics)
2 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- PersistenceServer Software Component: Web Shell
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-19/cve-2026-15748-forminator-forms-unauth-file-upload-rce · ATT&CK page ↗
Persistence TA0003
T1505.003Server Software Component: Web Shell×1
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-08-19/cve-2026-15748-forminator-forms-unauth-file-upload-rce · ATT&CK page ↗
Entries about WPMU DEV Forminator Forms (WordPress, 600,000+ installs), unauthenticated arbitrary file upload to remote code execution in handle_file_upload: the dangerous-extension blocklist matches MIME-type keys exactly and is bypassed by a pipe-alternative key, while a forged Select-field value overrides the upload field's own type configuration. CVSS 9.8, Wordfence as CNA. Exploitable only on forms carrying both a File Upload and a Select field. Fixed in 1.56.2 (2026-07-31); root-cause write-up published 2026-08-17, relayed by NCSC-CH 2026-08-18. No exploitation reported. (1)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
Where this entity is cited
Source distribution
- malware.news1 (33%)
- security-hub.ncsc.admin.ch1 (33%)
- thehackernews.com1 (33%)
External references
All cited sources (3)
- security-hub.ncsc.admin.chprimaryNCSC-CH Cyber Security Hubhttps://security-hub.ncsc.admin.ch/#/posts/12860
- malware.newsmalware.news (verbatim syndication of the Wordfence Intelligence post)https://malware.news/t/600-000-wordpress-sites-affected-by-arbitrary-file-upload-vulnerability-in-forminator-forms-wordpress-plugin/124864
- thehackernews.comThe Hacker News (quoting Wordfence)https://thehackernews.com/2026/08/forminator-wordpress-flaw-can-enable.html