Heise.De
Critical Vulnerabilities in WordPress Plugins Expose 600,000 Sites to Attacks
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
IT researchers have identified critical vulnerabilities in the Forminator Forms and Royal Elementor Addons WordPress plugins. The Forminator Forms plugin, used in over 600,000 installations, has a flaw (CVE-2026-15748) allowing unauthenticated users to upload malicious files, rated CVSS 9.8. This vulnerability can lead to full control of affected sites. Additionally, Royal Elementor Addons has two vulnerabilities (CVE-2026-17123 and CVE-2026-19217) that allow server-side request forgery and cross-site scripting attacks, respectively. The affected versions of these plugins are 1.56.1 and earlier for Forminator Forms, and prior to version 1.7.1066 for Royal Elementor Addons. Users are advised to update to the latest versions to mitigate these risks. The vulnerabilities were disclosed on August 12, 16, and 18, 2026.
Key Points: • Forminator Forms plugin vulnerability allows file uploads by unauthenticated users. • Over 600,000 WordPress sites are affected by these critical vulnerabilities. • Immediate updates to the latest plugin versions are essential to prevent exploitation.