{"schema_version":"1.0","report_url":"https://aretiq.ai/research/vul260818-cve-2026-15748-wpmu-dev-forminator-forms-select-field-injection-unrestricted-file-upload/","date":"2026-08-18","last_modified":"2026-08-18","cve":"CVE-2026-15748","title":"CVE-2026-15748 — WPMU DEV Forminator Forms Select Field Injection Unrestricted File Upload","vulnerability_name":"WPMU DEV Forminator Forms Select Field Injection Unrestricted File Upload","vendor":"WPMU DEV","product":"Forminator Forms","component":"Form Submission Handler","binary":"forminator","impact":"RCE","cwe":["CWE-434","CWE-20"],"severity":{"cvss_v4_score":8.2,"cvss_v4_vector":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P"},"attack_vector":"Network","patch_kb":"Forminator 1.56.2","poc_verified":true,"poc_download":"https://aretiq.ai/downloads/","tags":["wordpress","forminator","file-upload","rce","php","pre-auth"],"summary":"1. Overview A vulnerability exists in WPMU DEV’s Forminator Forms plugin for WordPress (600,000+ active installations) that allows unauthenticated attackers to upload arbitrary PHP files to the web server. The form processing logic trusts a client-supplied return key in Select field POST data, injecting attacker-controlled upload field configuration into the internal field processing array. Combined with a separate weakness in the file extension blocklist that uses exact-key matching, an attacker can bypass dangerous-extension filtering and upload executable PHP files. Successful exploitation achieves remote code execution under the web server’s user context. The vulnerability affects all Forminator Forms versions through 1.56.1 and was patched in version 1.56.2, released July 31, 2026.\n"}