<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Php on Aretiq AI</title><link>https://aretiq.ai/tags/php/</link><description>Recent content in Php on Aretiq AI</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 18 Aug 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://aretiq.ai/tags/php/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2026-15748 — WPMU DEV Forminator Forms Select Field Injection Unrestricted File Upload</title><link>https://aretiq.ai/research/vul260818-cve-2026-15748-wpmu-dev-forminator-forms-select-field-injection-unrestricted-file-upload/</link><pubDate>Tue, 18 Aug 2026 00:00:00 +0000</pubDate><guid>https://aretiq.ai/research/vul260818-cve-2026-15748-wpmu-dev-forminator-forms-select-field-injection-unrestricted-file-upload/</guid><description>&lt;h2 id="1-overview">1. Overview&lt;/h2>
&lt;p>A vulnerability exists in WPMU DEV&amp;rsquo;s Forminator Forms plugin for WordPress (600,000+ active installations) that allows unauthenticated attackers to upload arbitrary PHP files to the web server. The form processing logic trusts a client-supplied &lt;code>return&lt;/code> key in Select field POST data, injecting attacker-controlled upload field configuration into the internal field processing array. Combined with a separate weakness in the file extension blocklist that uses exact-key matching, an attacker can bypass dangerous-extension filtering and upload executable PHP files. Successful exploitation achieves remote code execution under the web server&amp;rsquo;s user context. The vulnerability affects all Forminator Forms versions through 1.56.1 and was patched in version 1.56.2, released July 31, 2026.&lt;/p></description></item></channel></rss>