CVE-2026-15748

Forminator Forms <= 1.56.1 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.


We have discovered 71,125 live websites that are affected by CVE-2026-15748.

Run a Free Instant Scan




Affected Software

Product  Forminator
Category Wordpress Plugins
Vulnerable Domains71,125 live websites (96% of Forminator install base)
Vulnerable Versions
  • from 0 through 1.56.1
Vulnerable Versions Count154 versions ( 99% of all versions)


Common Weakness Enumeration

CWE-434 Unrestricted Upload of File with Dangerous Type



Details

  • Published - Aug 18, 2026
  • Updated - Aug 18, 2026

Credits

  • daroo (finder)

Website Distribution by Country

Number of websites using CVE-2026-15748
United States22,373 websites



Germany5,774 websites
GB4,983 websites
France4,908 websites
Denmark3,455 websites
Canada2,217 websites
Netherlands2,193 websites
Italy2,128 websites
India1,996 websites
Australia1,822 websites

Website Distribution by TLD

Number of websites using CVE-2026-15748
.com29,906 websites
.org3,605 websites
.de3,378 websites
.co.uk3,164 websites
.dk2,995 websites
.fr2,656 websites
.nl2,009 websites
.com.au1,676 websites
.it1,553 websites
.ca1,253 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-15748

Top websites that are affected by CVE-2026-15748. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.com United States*,***
************.org France*,***
*******.com United States*,***
***********.net United States**,***
**************.com United States**,***
********.it Italy**,***
*********.gr Greece**,***
******.com Germany**,***
*****.com Canada**,***
********.org United States**,***
See full domain list

FAQ

CVE-2026-15748 is Unrestricted Upload of File with Dangerous Type in Forminator
A total of 71,125 websites have been identified as vulnerable to CVE-2026-15748, based on global website indexing conducted by WebTechSurvey.
The Forminator is affected by the CVE-2026-15748 vulnerability.
Forminator versions up to and including 1.56.1 are vulnerable to CVE-2026-15748.

References