SECURITY·중요도 10·2026. 08. 17.·The Hacker News

Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads

── KO ──────────────────

폼인에이터 워드프레스 플러그인에서 치명적인 원격 코드 실행 취약점이 발견됨.

폼인에이터 폼(WordPress 플러그인)의 심각한 보안 결함이 밝혀졌으며, 이로 인해 악의적인 PHP 파일 업로드를 통해 임의 코드 실행이 가능해질 수 있습니다. 이 취약점은 CVE-2026-15748로 추적되며 CVSS 점수는 9.8로 평가되었습니다. 60만 개 이상의 활성 설치를 가진 이 플러그인은 큰 위험을 내포하고 있습니다.


── EN ──────────────────

A critical RCE vulnerability found in the Forminator WordPress plugin.

A serious security flaw has been disclosed in the Forminator Forms plugin for WordPress, allowing for arbitrary code execution via malicious PHP uploads. This vulnerability is tracked as CVE-2026-15748 and has a CVSS score of 9.8 out of 10.0. With more than 600,000 active installations, this poses a significant risk to affected sites.

원문 보기 →목록으로