1 vulnerability across 1 product scored HIGH or above on August 18, 2026.

  • πŸ”΄ CRITICAL: 1

Exploit Status Upgrades

The following CVEs from previous bulletins have been upgraded based on new exploit intelligence:

  • [UPGRADED] CVE-2026-17083 (ibm/i) β€” F1: exploitable β†’ functional, AAS: 10.9 β†’ 12.9 (HIGH β†’ CRITICAL). Originally in 2026-08-12 bulletin.

πŸ”΄ [CRITICAL] wpmudev/forminator_forms_–_contact_form,payment_form&_custom_form_builder

1 CVE | CVSS 3.1: 9.8 | AAS 12.1

  • cpe:2.3:a:wpmudev:forminator_forms_contact_form_payment_form_custom_form_builder:*:*:*:*:*:*:*:*

WPMUDEV Forminator Forms β€” Critical Arbitrary File Upload

Forminator Forms (Contact Form, Payment Form & Custom Form Builder) for WordPress versions up to and including 1.56.1 is affected by one critical-severity vulnerability (CVE-2026-15748, CVSS 9.8). The flaw allows unauthenticated attackers to upload arbitrary files by bypassing the plugin’s dangerous-extension blocklist through pipe-alternative MIME type keys in combination with forged field values, potentially leading to full site compromise via remote code execution. A functional exploit is available, making this an urgent priority.

Any organization running Forminator Forms on WordPress should act immediately. Update to the latest patched version as soon as one is available, and review web server logs for signs of unexpected file uploads. If an update is not yet available, consider temporarily disabling file upload fields in Forminator forms or applying web application firewall rules to block suspicious upload requests. Refer to the vendor advisory for additional technical details.

Vendor Advisory