CVE-2026-15748 is an unauthenticated arbitrary file upload vulnerability in WPMU DEV Forminator Forms for WordPress versions through 1.56.1. The flaw is rooted in insufficient file-type validation in the upload handling path. An attacker can use crafted Select-field data to inject forged upload-field configuration into the public form-submission workflow, then bypass the dangerous-extension blocklist because it performs exact-key matching on MIME-type definitions that support pipe-separated alternatives. This permits upload of PHP or other potentially executable content that would otherwise be rejected. If the uploaded file is placed in a web-accessible location where server-side script execution is allowed, the issue leads to remote code execution.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains a working exploit PoC for CVE-2026-15748 affecting the WordPress Forminator Forms plugin <= 1.56.1. Structure is minimal: README.md documents the vulnerability chain, exploitation conditions, upload path behavior, and usage; poc.py is the main exploit; build_form.php is a lab helper that programmatically creates a vulnerable form with one upload field and one select field. The exploit is a web/network attack against a WordPress site. It abuses Forminator's handling of nested Select-field data to inject a forged upload field configuration into the server-side processing path. The forged configuration sets field_type=upload and supplies permissive file type settings, including an additional MIME regex key ph(p) that bypasses the plugin's literal php blocklist while still matching .php in WordPress filetype checks. The PoC then uploads a PHP webshell. The shell payload executes arbitrary commands from the c query parameter using shell_exec(). poc.py is described as 'live-first': it can fetch a target page, parse form_id, nonce, upload field names, and select field names from HTML, auto-fill plausible values for other required form fields, and submit the malicious multipart request. It also supports manual form_id/nonce input, candidate shell URL verification, and a local-only helper mode (--find-shell) that scans a Dockerized lab filesystem for the uploaded shell and removes a protective .htaccess file to demonstrate RCE. That local helper is explicitly gated to http://wordpresslab.test and http://localhost. The exploit's main capability is unauthenticated arbitrary file upload to Forminator's upload directory. Successful RCE depends on environmental conditions: the uploaded PHP file must be placed in a directory where PHP execution is not blocked by Forminator's .htaccess protections. The README emphasizes that arbitrary upload succeeds by default, but code execution generally requires a custom upload root missing .htaccess. As written, this is an operational PoC with a hardcoded PHP webshell payload rather than a generalized framework module.
Repository contains two separate security artifacts. The first, CVE-2026-15748-scanner.py, is a Python multi-target scanner for WordPress Forminator that performs passive version detection by requesting common plugin files under /wp-content/plugins/forminator/ and classifies versions <= 1.56.1 as vulnerable. It is a scanner/detection utility rather than an exploit. The second, and primary exploit content, is under CVE-2026-15826-fankh/. This is a standalone Python PoC plus a self-contained Docker lab. The PoC targets the WordPress User Profile Builder plugin authentication bypass (CVE-2026-15826) affecting versions up to 3.16.4. Its logic first fingerprints WordPress using endpoints such as /wp-login.php, /wp-json/wp/v2/, and /xmlrpc.php, then looks for plugin/registration indicators on the homepage and common registration paths. The active validation path uses a crafted registration condition based on a 61-70 character username to trigger the type-confusion bug described in the README. The intended result is issuance of an autologin nonce tied to administrator user ID 1, which can then be redeemed to establish an authenticated admin session. Repository structure for CVE-2026-15826 includes README documentation in English and Korean, poc.py as the main exploit/detection script, docker-compose.yml to launch vulnerable and patched Flask demo apps, and run-tests scripts for Linux/macOS and PowerShell. The vulnerable-app/app.py file is an intentionally vulnerable educational simulation exposing /register, /autologin, /profile, and /users; it demonstrates the bug by coercing a WP_Error-like object to integer 1 before checking for errors, thereby granting admin-bound nonce issuance. The patched-app/app.py file shows the corrected logic by validating types before nonce generation. Overall, this repository is best characterized as an educational exploit PoC plus lab environment for authentication bypass/admin takeover, alongside an unrelated WordPress plugin version scanner for another CVE.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
60 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical unauthenticated arbitrary file upload vulnerability in the Forminator Forms plugin for WordPress that can lead to remote code execution and full site compromise.
A critical vulnerability affecting the WordPress Forminator Forms plugin.
A critical unauthenticated arbitrary file upload vulnerability in the WordPress Forminator Forms plugin that can lead to remote code execution and full site compromise under certain storage configurations.
A critical unauthenticated arbitrary file upload vulnerability in the Forminator Forms WordPress plugin that can lead to remote code execution and full site compromise under vulnerable upload-storage configurations.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.