Forminator Forms WordPress Plugin Critical RCE Flaw Affects 600,000 Active Installations (CVE-2026-15748)
Scope: Forminator Forms WordPress Plugin (All Versions Prior to Patched Release)
Severity: Red
A critical remote code execution vulnerability (CVSS 9.8) disclosed today, August 18, 2026, in Forminator Forms, a WordPress plugin with over 600,000 active installations used to build contact forms, payment forms, quizzes, and polls, allows unauthenticated attackers to achieve arbitrary code execution on any WordPress site running a vulnerable version. Forminator Forms is one of the most popular form builder plugins in the WordPress ecosystem and is commonly deployed across Ugandan business websites, government portals, and educational institution sites for public-facing contact and registration forms. Organizations running WordPress with Forminator Forms installed must update the plugin immediately via the WordPress admin dashboard under Plugins, Updates, and audit recent form submission logs for suspicious activity as an indicator of prior exploitation.
The Uganda National CERT and Coordination Center (CERT.UG/CC) encourages users and administrators to review the recommendations and apply the necessary updates.