Critical Vulnerabilities in WordPress Plugins Expose 600,000 Sites to Attacks

Critical Vulnerabilities in WordPress Plugins Expose 600,000 Sites to Attacks

First seen 18 Aug 2026, 12:35 UTC Heise.DeCybersecuritynewswww.wordfence.com 90% similarity 78.0

Article Content

Browse articles
ThreatCluster

IT researchers have identified critical vulnerabilities in the Forminator Forms and Royal Elementor Addons WordPress plugins. The Forminator Forms plugin, used in over 600,000 installations, has a flaw (CVE-2026-15748) allowing unauthenticated users to upload malicious files, rated CVSS 9.8. This vulnerability can lead to full control of affected sites. Additionally, Royal Elementor Addons has two vulnerabilities (CVE-2026-17123 and CVE-2026-19217) that allow server-side request forgery and cross-site scripting attacks, respectively. The affected versions of these plugins are 1.56.1 and earlier for Forminator Forms, and prior to version 1.7.1066 for Royal Elementor Addons. Users are advised to update to the latest versions to mitigate these risks. The vulnerabilities were disclosed on August 12, 16, and 18, 2026.

Key Points: • Forminator Forms plugin vulnerability allows file uploads by unauthenticated users. • Over 600,000 WordPress sites are affected by these critical vulnerabilities. • Immediate updates to the latest plugin versions are essential to prevent exploitation.

ThreatCluster AI How this analysis works

Timeline

2026-08-12
CVE-2026-19217 published
A cross-site scripting vulnerability in Royal Elementor Addons was disclosed, affecting multiple installations.
Heise.De
2026-08-16
CVE-2026-17123 published
A server-side request forgery vulnerability in Royal Elementor Addons was disclosed.
Heise.De
2026-08-18
CVE-2026-15748 published
A critical vulnerability in Forminator Forms was disclosed, allowing file uploads by unauthenticated users.
Heise.De

Community

Browse all →

Tracked Entities in This Story