Current security vulnerabilities have been discovered in two widely used WordPress plugins. Forminator Forms and Royal Elementor Addons are affected. A vulnerability in Forminator Forms is particularly critical: Under certain conditions, threat actors can execute malicious code on a WordPress website without valid credentials and, in the worst case, take it over completely. The plugin is active on more than 600,000 WordPress websites.
A security vulnerability was also discovered in Royal Elementor Addons that could allow attackers to misuse a WordPress website to access internal systems.
In this article, we give an overview of the two vulnerabilities, explain which versions are affected, and show what measures WordPress website operators should take now.
What happened?
The critical security vulnerability CVE-2026-15748 has been discovered in the WordPress plugin Forminator Forms. The plugin is used, among other things, to integrate contact forms, surveys and other forms on WordPress websites.
The vulnerability affects versions up to and including 1.56.1 and allows attackers to upload manipulated files to the web server under certain conditions. Particularly critical: No valid access data is required for an attack .
The prerequisite for a successful attack is that a form created with Forminator on the affected website contains both a field for file uploads and a selection field.
No valid credentials are required for the attack. Instead, the attackers use the vulnerabilities to bypass security mechanisms and take control of a vulnerable WordPress installation. After a successful compromise, web shells (programs that give attackers permanent remote access to the server) or other backdoors can be installed, websites can be manipulated, malware can be spread or confidential data can be stolen.
What can I do?
We recommend the following measures to companies and website operators
Further information on the vulnerability can be found at Wordfence as well as at All About Security.
What happened?
A security vulnerability was also discovered in the WordPress plugin Royal Elementor Addons. According to GitHub, the CVE-2026-17123 vulnerability affects versions up to and including 1.7.1064 and was rated “high” with a CVSS score of 8.8 out of 10 points.
Unlike the vulnerability in Forminator Forms, an attacker already needs a WordPress user account with at least contributor or employee rights. However, if criminals have already gained access to a WordPress website – for example, by exploiting the vulnerability in Forminator Forms described above – they may be able to create a user account with the necessary rights and then exploit the vulnerability in Royal Elementor Addons. In this way, several vulnerabilities can be chained together.
Note: Even already known and not yet closed WordPress vulnerabilities continue to be exploited by criminals. We have already pointed out corresponding attack possibilities and the use of webshells as a permanent backdoor in our danger warning for WP2Shell.
How can the vulnerability be exploited?
The vulnerability is a so-called Server-Side Request Forgery (SSRF). Put simply, an attacker can trick the affected web server into sending requests to other systems on its behalf.
As a result, the WordPress website could be misused as a starting point for access to internal systems and services that are normally not directly accessible from the Internet. In this way, attackers could request or change internal information.
What can I do?
We recommend the following measures to companies and website operators:
The current vulnerabilities show once again that not only WordPress itself, but also installed plugins need to be checked and updated regularly. Companies should therefore check which extensions are used on their WordPress websites, remove unnecessary plug-ins and install available security updates as soon as possible.
Another note: If possible, enable automatic updates for trusted WordPress plugins so that important security updates are installed promptly.
our current incident response cases, we are increasingly observing attacks on WordPress websites in which known vulnerabilities in the CMS or plug-ins are exploited. The consequences range from the complete takeover of the website and the theft of access data to the theft of sensitive customer data. Often, outdated systems that are not updated in time are the cause.
We therefore recommend consistent patch management for WordPress and all plugins used. In addition, a web application firewall (WAF) can help to detect and block attack attempts at an early stage.
Do you want to stay informed about current threats and security vulnerabilities?
Subscribe to our newsletter and receive important warnings, recommendations for action and assessments of current cyber risks directly in your inbox.
Sources & Further Information
Forminator Forms – CVE-2026-15748
Royal Elementor Addons – CVE-2026-17123