Security News Forminator WordPress Flaw Can Enable Unauthenticated RCE via Malicious PHP Uploads TheHackerNews Daniel Bender 17 Aug 2026 Share Forminator CVE-2026-15748 lets unauthenticated attackers upload PHP files and reach RCE on sites using vulnerable form configurations.