BoletimSec•August 19, 2026•🇵🇹Translated from Portuguese

Critical Vulnerability in Forminator Forms WordPress Plugin Enables Unauthenticated Remote Code Execution

A critical vulnerability in the Forminator Forms plugin for WordPress can allow unauthenticated attackers to upload malicious PHP files and, under certain conditions, execute arbitrary code on the server.

The flaw, identified as CVE-2026-15748 and scored 9.8 on the CVSS scale, affects all versions up to 1.56.1. The plugin, which boasts more than 600,000 active installations, is widely used to create forms, surveys, payment integrations, quizzes, and file upload fields.

Exploitation requires a published form that simultaneously includes both a File Upload field and a Select field. Attackers can manipulate data submitted through the Select field to create a fake upload configuration accepted by the plugin. This technique also bypasses restrictions on dangerous file extensions.

By using a variation in file type identification, the attacker can make a PHP file pass the checks intended to block executable content. Once the file is placed in a web-accessible directory, the attacker can execute commands, install web shells, steal credentials, access databases, and fully take over the site.

The vulnerability was fixed in Forminator 1.56.2, released at the end of July. Subsequent versions, including 1.57.0, are now available to users.

Related articles

Hispasec•Vulnerabilities & Exploits

CISA Sets September 30 Deadline for Federal Agencies to Patch Actively Exploited Citrix NetScaler Zero-Days

CISA has ordered U.S. federal agencies to apply patches by September 30 for two actively exploited zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway. The flaws, tracked as CVE-2026-88771 and CVE-2026-88772, enable unauthenticated remote code execution under default configurations and affect systems commonly exposed to the internet. CVE-2026-88771 allows remote code execution without authentication on NetScaler ADC and Gateway, while CVE-2026-88772 can trigger remote code execution or denial of service via a memory overflow when DTLS is enabled on VPN vServers. Citrix has released fixes for versions 14.1 and 13.1, including FIPS and NDcPP builds, with minimum required builds of 14.1-73.37 and 13.1-64.23. The advisory also covers six additional vulnerabilities from CVE-2026-88773 to CVE-2026-88778 involving HTTP request smuggling and TCP ISN prediction issues. Unsupported branches NetScaler 12.1 and 13.0 receive no patches, requiring immediate migration. Organizations are advised to inventory instances, check for compromise indicators before patching, and preserve forensic evidence.

BoletimSec•Vulnerabilities & Exploits

CSRF Flaw in Elementor Allows Admin Account Creation on Over 2 Million WordPress Sites

A critical CSRF vulnerability has been identified in the Elementor page builder plugin for WordPress, affecting versions 4.3.0 and 4.3.1. The issue enables attackers to create administrator accounts on target sites by exploiting improper handling of CSRF protections in the Editor Events module. With a CVSS score of 8.8, the flaw impacts more than 2 million installations out of over 10 million total WordPress sites using the plugin. No CVE identifier had been assigned at the time of disclosure on September 26. The vulnerability was fixed in version 4.3.2, and users are urged to update immediately. The discovery is credited to researcher Saggre following responsible disclosure, with no public records of active exploitation noted at the time of analysis.

BoletimSec•Vulnerabilities & Exploits

Mandiant Uncovers WAF Bypass Campaign Exploiting Critical Oracle PeopleSoft CVE-2026-35273

Mandiant has identified an active campaign abusing CVE-2026-35273, a critical unauthenticated remote code execution flaw in Oracle PeopleSoft's Environment Management Hub (PSEMHUB). Attackers bypass web application firewalls by replacing the literal path /PSEMHUB/ with /%50SEMHUB/, exploiting the fact that many WAF rules inspect the URL before decoding while the PeopleSoft application server decodes it afterward. The exploitation chain relies on Java object deserialization via POST requests to /%50SEMHUB/hub, allowing deployment of two distinct JSP web shells. The group then establishes persistence with a trojanized installer that drops the SIDEEYE backdoor along with Neo-reGeorg and MeshAgent. Activity attributed to UNC6240, linked to ShinyHunters, began as a zero-day against educational institutions in June 2026 and has since expanded to higher education, technology, healthcare, agriculture, transportation, and government sectors.

Habr•Vulnerabilities & Exploits

Dissecting CVE-2026-83557 in jackson-databind: Why Not Every CVE Requires Immediate Panic

A detailed analysis of CVE-2026-83557 reveals that the vulnerability in jackson-databind affects only a narrow set of configurations involving polymorphic deserialization with the Comparable base type. The flaw stems from an incomplete denylist in DefaultBaseTypeLimitingValidator, which overlooks java.lang.Comparable when the MapperFeature.BLOCK_UNSAFE_POLYMORPHIC_BASE_TYPES flag is explicitly enabled. Researchers constructed working proof-of-concept exploits showing that an attacker can instantiate classes such as java.io.File, but only when the property is declared as Comparable<?> and the protective flag is active. The issue impacts versions 2.11 through 2.22.1, yet the CVSS score of 5.6 reflects its moderate real-world risk because most applications lack the required Comparable-typed polymorphic fields. Patching introduces its own trade-off by blocking legitimate Comparable subclasses, forcing developers to implement custom BasicPolymorphicTypeValidator allowlists. The case highlights how dependency scanners often flag CVEs without considering application-specific configuration and DTO structures.