Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

August 17, 2026 1 Min Read 0

Threat Intelligence Brief

Curated summary with source attribution

Source: thehackernews.com

Threat Risk: High
Victim: WordPress site administrators
Incident: Remote Code Execution and Authentication Bypass vulnerabilities in widely used WordPress plugins.
Impact: Full administrative takeover and arbitrary code execution on the web server.
Attacker: Unidentified threat actors
Analysis: The vulnerability arises from insufficient file type validation in the plugin’s upload handler, allowing attackers to bypass extension blocklists. When custom storage roots are configured, the usual .htaccess protections are bypassed, facilitating direct PHP execution. This creates a high-risk path to full server compromise for unauthenticated users.
Recommendations: Update the Forminator plugin to version 1.56.2 or later immediately.; Verify that custom file upload storage directories have strict execution permissions.; Update the User Profile Builder plugin to version 3.16.5 or later to prevent admin account takeover.
Source: The Hacker News

Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source

Leave a Reply

Your email address will not be published. Required fields are marked *