build1 distinct publisher
Forminator trusts a forged upload: a dropdown flaw exposes 600,000 WordPress sites to RCE
CVE-2026-15748 lets an unauthenticated attacker hide upload settings inside a Select field, so any site below 1.56.1 with a Select and a File Upload field is one request from a PHP file.
Publishers:dev.to
Reality
- Evidence60
- Adoption40
- Hype gap+18
- Incentives
- Insufficient
- Confidence52