Executive brief
Formidable Charts is a WordPress plugin that extends the Formidable Forms platform to render data visualizations. A directory traversal vulnerability in versions up to 2.0.1 allows unauthenticated attackers to read arbitrary files from the web server, potentially exposing sensitive configuration files, database credentials, or other confidential data stored on the server.
Technical details
The vulnerability is a directory traversal (path traversal) flaw in the 'frm_graph' parameter of the Formidable Charts plugin. Unauthenticated attackers can exploit this to access arbitrary files on the server without requiring authentication. The attack requires that Formidable Forms (Lite or Pro) and Formidable Charts are both active, and that the wp-content/uploads/frm-charts/ directory exists (typically created after rendering an image-format chart). The vulnerability was patched in version 2.0.2, released on August 25, 2026, which improved the security of the graph image processing.
Affected products
- Formidable Charts up to 2.0.1
- Formidable Forms Lite all versions (required for exploitation)
- Formidable Forms Pro all versions (required for exploitation)
Timeline
- 2026-08-26: disclosed: CVE-2026-15990 published
- 2026-08-25: patched: Charts v2.0.2 released with security improvements to graph image handling