A critical flaw in Forminator Forms, a WordPress form builder with more than 600,000 active installations, lets an unauthenticated attacker upload executable PHP files to a vulnerable site. Tracked as CVE-2026-15748 and rated 9.8 on the CVSS scale, it was fixed in version 1.56.2 on 31 July 2026. Roughly half of installations were still running […]
Read More