Critical Vulnerability Discovered
A critical security flaw, tracked as CVE-2026-15748, has been identified in the Forminator Forms WordPress plugin. This vulnerability, rated 9.8 out of 10.0 on the CVSS scoring system, could allow unauthenticated attackers to achieve arbitrary code execution on affected websites. The plugin is actively installed on over 600,000 WordPress sites.
Mechanism of Exploitation
The flaw stems from insufficient file type validation within the "handle_file_upload()" function, enabling attackers to upload arbitrary files, including executable PHP files. For successful exploitation, a site must have a form containing both a File Upload field and a Select field. Attackers can bypass the dangerous-extension blocklist by using pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configurations injected via a forged Select field value.
Impact and Remediation
Upon successful exploitation, an attacker can upload a specially crafted PHP file and achieve remote code execution, potentially leading to complete site compromise. While the default configuration uploads files to a directory protected by an .htaccess file preventing PHP execution, sites with a Custom File Upload Storage root may lack this safeguard. The vulnerability impacts all versions of the plugin up to and including 1.56.1 and has been addressed in version 1.56.2, released on July 31, 2026. Users are advised to update their plugins immediately.
Updates
🕒 2026-09-26 · new reporting from The Hacker News
- Elementor CSRF vulnerability has a CVSS score of 8.8.
- Elementor CSRF vulnerability allows attackers to create a second administrator account.
- Elementor CSRF vulnerability does not require JavaScript, a submitted form, or a web page under attacker control.
- Elementor CSRF vulnerability link can be a plain anchor tag in an email, chat message, or comment.
🕒 2026-09-25 · new reporting from BleepingComputer
- Elementor plugin has a CSRF vulnerability.
- Elementor CSRF vulnerability affects versions 4.3.0 and 4.3.1.
- Elementor CSRF vulnerability allows unauthenticated attackers to create administrator accounts.
- Elementor CSRF vulnerability affects up to 2 million websites.
- Elementor CSRF vulnerability was patched in version 4.3.2.
- Elementor CSRF vulnerability was reported by Saggre to Patchstack.
- Elementor CSRF vulnerability was reported on September 22.
- Elementor released a fix two days after the report.
- Elementor CSRF flaw is in the Editor Events module.
- Elementor Website Builder is active on 10 million websites.
🕒 2026-09-24 · new reporting from The Hacker News, SecurityWeek
- Exploitation requires the active theme to contain a top-level directory starting with 'page-'.
- Exploitation requires a chosen local .php target file to exist and be readable by the web server account.
- Previdian observed exploitation attempts from IP address 104.194.9.227 in New Jersey.
- The pearcmd.php PEAR->RCE transition can be used when register_argc_argv is On.
- The official PHP image for Docker is affected by the vulnerability.
- The default cPanel configuration is affected when PHP prior to 8.5 is in use.
🕒 2026-09-23 · new reporting from BleepingComputer
- Attackers are exploiting CVE-2026-87902 to write files and execute shell commands.
- Initial attack traffic for CVE-2026-87902 started less than five hours after the patch release.
- Malicious activity for CVE-2026-87902 increased tenfold.
- Patchstack observed the first malicious requests for CVE-2026-87902 at 17:44 UTC on September 22.
- Robert Ressl discovered CVE-2026-87902.
🕒 2026-09-22 · new reporting from The Hacker News
- WordPress core has a critical vulnerability (CVE-2026-87902).
- WordPress core vulnerability allows unauthenticated attackers to load arbitrary PHP files.
- WordPress core vulnerability affects versions 4.7.0 through 7.1.1.
- WordPress core vulnerability has a CVSS score of 9.2.
- WordPress core vulnerability was fixed on September 22.
- WordPress core vulnerability fix was backported to version 4.7.37.
🕒 2026-09-22 · new reporting from Hacker News Front Page
- WordPress 7.1.2 patches an unauthenticated path traversal vulnerability.
- The vulnerability allows including arbitrary local PHP files.
- RCE is possible under specific server and theme configurations.
- The flaw affects legacy Twenty Twelve and Twenty Fourteen themes.
- The flaw affects popular third-party themes like Neve, Hestia, and Sydney.
- The fix has been backported to all WordPress branches back to 4.7.
- The vulnerability is in get_page_template() page-template resolution.
🕒 2026-09-18 · new reporting from The Hacker News
- WooCommerce Wholesale Lead Capture plugin has a critical RCE vulnerability (CVE-2026-27540).
- WooCommerce Wholesale Lead Capture vulnerability affects over 6,000 active installations.
- Wordfence blocked over 100,000 exploit attempts targeting WooCommerce Wholesale Lead Capture since June 2026.
- WooCommerce Wholesale Lead Capture vulnerability is an arbitrary file upload due to missing file type validation.
- WooCommerce Wholesale Lead Capture vulnerability is in the AJAX action "wwlc_file_upload_handler".
- WooCommerce Wholesale Lead Capture vulnerability affects all versions up to, and including, 2.0.3.1.
- Attackers submit crafted requests to "wwlc_file_upload_handler" with a forged file_settings parameter.
- Attackers upload a malicious PHP file named "shell.php".
🕒 2026-09-05 · new reporting from SecurityWeek
- Elementor Pro is a paid version of the Elementor plugin.
- Elementor Pro has a Form widget with File Upload fields.
- The vulnerability allows unauthenticated attackers to upload arbitrary PHP files.
- The validation loop encounters an upload slot marked as empty, triggering an error and returning.
- The vulnerability results in checks never being applied to remaining files uploaded through the same form field.
- An attacker can submit an upload field as an array with an empty slot and a PHP payload.
🕒 2026-09-04 · new reporting from The Hacker News
- Super Forms plugin has a critical RCE vulnerability (CVE-2026-14894).
- Super Forms vulnerability is a missing file type validation flaw.
- Super Forms vulnerability was fixed in version 6.3.314.
- Elementor Pro vulnerability has a CVSS score of 9.0/9.8.
- Wordfence blocked over 440,000 exploit attempts targeting Super Forms and Elementor Pro.
🕒 2026-09-03 · new reporting from BleepingComputer
- Elementor Pro vulnerability is actively exploited to upload webshells.
- Elementor Pro plugin has over 6 million active installations.
- Elementor Pro vulnerability was patched on August 19.
- Wordfence blocked almost 200,000 exploitation attempts.
- Uploaded payload is stored under /wp-content/uploads/elementor/forms/.
🕒 2026-09-03 · new reporting from SecurityWeek
- All-in-One WP Migration and Backup vulnerability has a CVSS score of 8.8.
- All-in-One WP Migration and Backup vulnerability is in the archive restore functionality.
- All-in-One WP Migration and Backup vulnerability involves insufficient escaping of user-supplied input.
- All-in-One WP Migration and Backup vulnerability involves insufficiently prepared SQL queries.
- All-in-One WP Migration and Backup vulnerability allows attackers to use WordPress core's trackback functionality.
- All-in-One WP Migration and Backup vulnerability allows attackers to deploy malicious plugins.
- All-in-One WP Migration and Backup plugin packages sites into .wpress archives.
- All-in-One WP Migration and Backup import operation is unauthenticated.
- All-in-One WP Migration and Backup vulnerability allows submitting two trackbacks to a public post.
🕒 2026-09-02 · new reporting from BleepingComputer
- All-in-One WP Migration and Backup plugin has a high-severity SQL injection vulnerability (CVE-2026-19949).
- All-in-One WP Migration and Backup vulnerability affects versions through 7.109.
- All-in-One WP Migration and Backup vulnerability allows unauthenticated attackers to execute remote code.
- All-in-One WP Migration and Backup vulnerability was discovered by Jack Taylor.
- All-in-One WP Migration and Backup vulnerability was reported in mid-August through Wordfence.
- All-in-One WP Migration and Backup vulnerability is a second-order SQL injection.
- All-in-One WP Migration and Backup vulnerability involves incorrect parsing of escaped backslashes and quotation marks.
- All-in-One WP Migration and Backup vulnerability requires an administrator to export and import the site.
- All-in-One WP Migration and Backup vulnerability can expose the plugin’s secret import key (ai1wm_secret_key).
- All-in-One WP Migration and Backup plugin has 3.25 million sites remaining vulnerable.
🕒 2026-08-29 · new reporting from The Hacker News
- WPMU DEV Dashboard plugin has an authentication bypass flaw (CVE-2026-76581).
- WPMU DEV Dashboard flaw affects all versions up to 5.0.1.
- WPMU DEV Dashboard flaw requires Hub Single-Sign On (SSO) enabled and mapped to an administrator.
- Avada theme has an arbitrary file write flaw (CVE-2026-18431).
- Avada theme flaw affects all versions up to 7.16.
- Avada theme flaw requires Fusion Builder plugin up to 3.16 to be installed and active.
🕒 2026-08-28 · new reporting from BleepingComputer
- GiveWP WordPress donation plugin has a critical RCE vulnerability (CVE-2026-82222).
- GiveWP vulnerability affects versions through 4.16.7.1.
- GiveWP vulnerability allows unauthenticated attackers to execute arbitrary commands.
- GiveWP vulnerability was reported by Udin Chan on July 28 via Patchstack.
- GiveWP plugin has over 100,000 installs.
- GiveWP vulnerability chains three issues: unsafe unserialization, attacker-controlled serialized objects, and a gadget chain.
- GiveWP vulnerability exploitation requires an attacker account on the target site.
- GiveWP exposes an unauthenticated registration action (give_action=user_register).
🕒 2026-08-20 · new reporting from BleepingComputer
- Elementor Pro vulnerability is patched in version 4.2.2.
- Elementor Pro flaw involves separate loops for validation and processing.
- Elementor Pro flaw allows attackers to use an empty filename entry to bypass validation.
🕒 2026-08-20 · new reporting from The Hacker News
- Elementor Pro WordPress plugin has a critical RCE vulnerability (CVE-2026-32475).
- Elementor Pro vulnerability affects all plugin versions up to 4.2.1.
- Elementor Pro vulnerability requires a published Elementor page with a File Upload form widget.
- Elementor Pro flaw is in the Forms module's File Upload field.
- Elementor Pro flaw involves extension check and file-move step running in separate loops.
- Elementor Pro flaw allows attackers to submit two file parts for the same field.
🕒 2026-08-18 · new reporting from SecurityWeek
- The vulnerability has a CVSS score of 9.8.
- The flaw is an arbitrary file upload via the handle_file_upload function.
- The issue is a combination of several weaknesses.
- Attackers can forge records using the Select field.
- Attackers can take control of the field configuration passed to the upload function.
- Attackers can bypass the plugin’s blocklist of dangerous file types.
- The blocklist performs exact-key matching bypassed by pipe-alternative MIME type keys.
- A public submission handler trusts attacker-controlled upload field configuration.
✨ This summary was generated by AI from the outlets' reporting listed below.
It is not independently verified and may contain errors — check the original sources.
How BrevFeed works →
The daily brief
One email each morning: the day's tech stories, clustered across outlets and
summarized. No account needed.
One email a day. Unsubscribe in one click, any time.
Today's brief
Spend a few minutes, get the whole day. Every topic's top stories in one hands-free
rundown — listen, watch, or read the transcript.
~16 min ·
14 stories · Oct 01
▶ Play today's brief
New every morning, and the back catalogue is archived by date.
How outlets covered it
A high-severity cross-site request forgery (CSRF) vulnerability in Elementor Website Builder WordPress plugin versions 4.3.0 and 4.3.1 allows unauthenticated attackers to create rogue administrator accounts and take control of affected sites. The flaw, with a CVSS score of 8.8, affects over 2 million sites and is patched in version 4.3.2.
A cross-site request forgery (CSRF) vulnerability in Elementor WordPress plugin versions 4.3.0 and 4.3.1 allowed unauthenticated attackers to create administrator accounts. This flaw affects up to 2 million websites and was patched in version 4.3.2, which users are advised to install immediately.
A critical path traversal vulnerability (CVE-2026-87902) in WordPress, allowing unauthenticated remote code execution under specific conditions, was exploited within hours of its public disclosure. Attackers used the patch's diff to create exploits, leading to active compromises on affected sites.
Threat actors are actively exploiting CVE-2026-87902, a critical WordPress vulnerability, allowing unauthenticated remote code execution. Exploitation attempts were observed shortly after the flaw's public disclosure, targeting specific server configurations.
Threat actors are now exploiting CVE-2026-87902, a critical unauthenticated path traversal flaw in WordPress, to write files and execute shell commands on vulnerable sites. This vulnerability, rated 9.2 out of 10, can lead to remote code execution under specific conditions, affecting WordPress installations that have not yet updated to version 7.1.2 or later.
WordPress released an urgent patch for a critical vulnerability (CVE-2026-87902) in its core software that could allow unauthenticated attackers to load arbitrary PHP files and, on some servers, execute remote code. The flaw, rated 9.2 CVSS, affects all versions from 4.7.0 through 7.1.1, requiring immediate updates for site owners.
WordPress has released version 7.1.2 to patch an unauthenticated path traversal vulnerability that could lead to conditional remote code execution (RCE). The flaw allowed an attacker to include arbitrary local PHP files, potentially enabling RCE under specific server and theme configurations. This fix addresses a significant security risk for WordPress installations meeting the preconditions.
Threat actors are exploiting a critical vulnerability (CVE-2026-27540) in the WooCommerce Wholesale Lead Capture WordPress plugin, allowing unauthenticated attackers to upload arbitrary files and achieve remote code execution. This flaw impacts over 6,000 active installations and has led to over 100,000 exploit attempts blocked by Wordfence since June 2026.
A critical-severity vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin is being actively exploited to hack websites. The flaw allows unauthenticated attackers to upload arbitrary PHP files, potentially leading to full site compromise, and was patched in version 4.2.2.
Threat actors are actively exploiting two critical remote code execution (RCE) vulnerabilities in the WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475). These flaws allow unauthenticated attackers to upload malicious files, potentially leading to full site compromise, and over 440,000 exploit attempts have been blocked by Wordfence.
A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin is being actively exploited to upload webshells and execute arbitrary commands. The flaw, present in versions 4.2.1 and earlier, allows attackers to bypass file upload validation, impacting over 6 million active installations.
A high-severity vulnerability (CVE-2026-19949) in the All-in-One WP Migration and Backup WordPress plugin exposes over 3 million websites to remote code execution (RCE) attacks. The flaw, a second-order SQL injection, allows attackers to extract a secret key and deploy malicious plugins, leading to site compromise.
A high-severity SQL injection vulnerability (CVE-2026-19949) in the All-in-One WP Migration and Backup plugin for WordPress allows unauthenticated attackers to execute remote code and take control of affected websites. Approximately 3.25 million sites remain vulnerable as only 35% of the plugin's user base has updated to the patched version.
Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP. These vulnerabilities could lead to authentication bypass, account takeover, arbitrary file write, and remote code execution, enabling full site compromise.
A critical vulnerability, CVE-2026-82222, in the GiveWP WordPress donation plugin allows unauthenticated attackers to execute arbitrary commands on hosting servers. This flaw affects GiveWP versions through 4.16.7.1 and could lead to full server compromise for websites using the plugin.
A critical vulnerability, CVE-2026-32475, in Elementor Pro versions before 4.2.2 allows attackers to upload executable files, leading to remote code execution on affected WordPress sites. This flaw impacts sites using the popular Elementor Pro plugin, potentially compromising a significant number of higher-grade WordPress platforms.
A critical vulnerability (CVE-2026-32475) in the Elementor Pro WordPress plugin allows unauthenticated attackers to upload malicious PHP files and execute code remotely. This flaw, rated 9.0 CVSS, impacts all plugin versions up to 4.2.1 and requires a published Elementor page with a File Upload form widget to be exploitable.
A critical vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin allows unauthenticated attackers to upload executable files, potentially leading to remote code execution. This flaw affects approximately 300,000 websites running vulnerable versions of the plugin, which was patched in version 1.56.2 on July 31.
A critical security vulnerability (CVE-2026-15748) in the Forminator Forms WordPress plugin allows unauthenticated attackers to upload malicious PHP files, leading to remote code execution and site compromise. The flaw, rated 9.8 on CVSS, affects over 600,000 active installations and requires specific form configurations for exploitation, but has been patched in version 1.56.2.