LIVE · cybersecurity feed
Live wire
OpenAI Announced $1B in Defensive Tools for Water UtilitiesAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS CredentialsCVE-2026-59346 · Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host CodeCVE-2026-32475 · Elementor Pro WordPress Plugin Vulnerability Exploited to Hack SitesBroadcom Patches Critical VMware Workstation and Fusion VM-Escape VulnerabilitiesHackers Leak Millions of Airport Passenger Records After Ransom RefusalUsing a VM to Contain an AI AgentCVE-2026-73749 · HPE Patches Critical RCE Vulnerabilities in AOS-CXCVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update release
cve recordcritical

CVE-2026-15748

Published
CVSS9.8
Severitycritical
WeaknessCWE-434
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

The Forminator Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 1.56.1 via the handle_file_upload function. This is due to insufficient file type validation in handle_file_upload, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-15748

CVE-2026-19478high

⚡ Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

This week's cybersecurity landscape features AI-powered attacks targeting industrial control systems, a critical vulnerability in GitLab being actively exploited, and the discovery of trojanized npm packages delivering a sophisticated Linux backdoor. Additionally, researchers revealed a method to exploit expired credit cards for contactless payments, and several other vulnerabilities across various software platforms were highlighted.

CVE-2026-15748critical

Forminator WordPress Plugin Vulnerable to Remote Code Execution

A critical vulnerability in the Forminator WordPress plugin, used by over 600,000 sites, allows unauthenticated attackers to execute arbitrary code. This is achieved by exploiting a flaw that permits the upload of malicious PHP files. The vulnerability has a high severity rating.