Blog · 19 August 2026

A WordPress form plugin flaw is a reminder to check the boring bits

Website contact form upload field blocked by a security shield to show a plugin file upload vulnerability.

A critical flaw in Forminator, a popular WordPress form builder plugin, was reported this week after researchers found it could let unauthenticated attackers upload malicious PHP files on some sites.[1]

The headline number is uncomfortable: WordPress.org lists Forminator at more than 600,000 active installs, and The Hacker News reports the flaw as CVE-2026-15748 with a CVSS score of 9.8.[1][2]

There is a bit of nuance, because the issue is not automatically exploitable on every site with the plugin installed. According to the report, the risky setup needs a form containing both a file upload field and a select field, and sites using a custom upload storage location may miss the .htaccess protection that normally stops uploaded PHP from running.[1]

That nuance matters, but it should not become an excuse to shrug. Most business owners do not know which fields are on which form, where uploaded files are stored, or whether last week’s plugin update actually made it onto the live site. Fair enough. That is exactly why website maintenance has to be treated as maintenance, not as something you remember after Google flags the site as dangerous.

The fix for this specific Forminator issue landed in version 1.56.2 on 30 July 2026, and WordPress.org shows a string of further security fixes published on 18 August 2026.[2]

For a small business, the lesson is simple: the dangerous part is not only the vulnerability. It is the gap between a fix being available and somebody checking that your site has it.

Why this matters for ordinary business websites

Contact forms are boring until they are not.

They sit on quote pages, support pages, booking pages, job application pages and payment pages. They accept files. They send emails. They store submissions. They often connect to CRMs, payment processors or marketing tools.

That makes them useful. It also makes them a decent target.

A compromised form plugin can be more than a broken enquiry form. Depending on the site and server setup, it can give an attacker a way to plant files, change pages, steal form submissions, redirect visitors or use the site to attack someone else.[1]

If your website brings in leads, bookings or payments, that is not a “web problem”. It is an operations problem.

What businesses should check this week

  1. Check whether your site uses Forminator. If it does, make sure it is updated beyond 1.56.2. The current WordPress.org plugin record shows version 1.57.1, last updated on 18 August 2026.[2]
  2. Check forms that allow file uploads. File upload fields are useful for CVs, documents and support screenshots, but they need tighter handling than a standard text field. Check allowed file types, upload paths and who can access uploaded files.
  3. Check whether plugin updates are actually being monitored. Auto-updates help, but they are not a maintenance plan by themselves. Someone still needs to check failed updates, plugin conflicts, abandoned plugins and backups before larger changes.
  4. Check backups before you need them. The NCSC’s small business guidance points businesses toward backups, protected devices and accounts, and scam awareness. That is not glamorous advice, but it is the stuff that decides whether a bad morning becomes a full week of pain.[3]
  5. Check recovery, not just prevention. A clean backup, separate admin accounts, access logs and a known recovery process are what let you move quickly if a site is compromised. Without those, every fix starts with guesswork.

The BMT view

This is the kind of issue we expect to keep seeing. WordPress is popular, plugins move quickly, and business websites keep picking up more jobs: forms, bookings, payments, client uploads, analytics, chat widgets, automations.

None of that is bad. It just needs ownership.

If your site has not had a proper plugin, backup and hosting review in a while, this is a sensible moment to do it. Not because the sky is falling, but because the fix is usually cheaper before something breaks.

B&M Technologies can review your WordPress setup, check plugin exposure, confirm backups, tighten hosting security and put a practical recovery plan around the site. If you want a calm second pair of eyes on it, speak to BMT before a routine plugin issue turns into an incident.

Practical takeaways

  • Update Forminator if it is installed, and confirm the live version afterwards.
  • Pay extra attention to forms that allow file uploads.
  • Keep backups separate from the website hosting account.
  • Test recovery, even if it is only a small restore drill.
  • Review old plugins and remove anything the site no longer uses.
  • Make one person or provider clearly responsible for website maintenance.

Need a second pair of eyes?

Worried about your WordPress site or not sure what plugins are running? B&M Technologies can run a practical website security and hosting review, then give you a clear fix list without the scare tactics.

Sources

  1. The Hacker News: Forminator WordPress flaw can enable malicious PHP uploads
  2. WordPress.org plugin information: Forminator
  3. NCSC Small Business Guide

← Back to all articles

Want to talk through anything in this article? Contact us and we’ll help.

Reviews

Testimonials