Back Heise.De WordPress plugin Forminator Forms: Critical vulnerability allows code smuggling
IT researchers have discovered critical vulnerabilities in several popular WordPress plugins. They allow attackers to inject and execute malicious code, among other things. The WordPress add-ons Forminator Forms and Royal Elementor Addons are affected.
The IT security company Wordfence is currently warning of a vulnerability in Forminator Forms up to and including version 1.56.1, which allows unauthenticated actors to upload arbitrary files. There is no sufficient check of the file type in an input field, and a blocklist of dangerous extensions can be bypassed by skillful use of MIME types. The uploaded files can be executable, making it possible to inject and execute malicious code (CVE-2026-15748, CVSS 9.8 , risk “ critical ”). The extension is used in more than 600,000 active installations, Wordfence explains. IT managers should ensure that the bug-fixed version 1.56.2 or newer of Forminator Forms is used.
In addition, the IT researchers from Wordfence have identified two vulnerabilities in Royal Elementor Addons. According to the WordPress plugin page , these are also used in more than 600,000 active installations. Attackers with at least “Contributor” access can exploit a server-side request forgery vulnerability and thus reach internal systems that are actually inaccessible, explain the IT researchers in their analysis (CVE-2026-17123, CVSS 8.8 , risk “ high ”). Furthermore, users with Contributor rights or higher can exploit a Cross-Site Scripting vulnerability and inject arbitrary web scripts into pages, which are then executed when called (CVE-2026-19217, CVSS 6.4 , risk “ medium ”).
Version 1.7.1066 of Royal Elementor Addons is currently available and no longer contains the vulnerabilities. Admins should check if the current version is already installed and update promptly if necessary.
This article was originally published in German . It was translated with technical assistance and editorially reviewed before publication.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
