Junglewise Threat Intelligence

CVE-2026-57815: WPMU DEV Forminator path traversal and arbitrary file download

CVE-2026-57815 · Severity: high · CVSS 7.5 · Published 2026-07-13

Technologies: WPMU DEV Forminator. Vendors: WPMU DEV.

Executive brief

Forminator is a popular WordPress plugin used to create forms, polls, and quizzes. A security flaw in this plugin allows unauthorized individuals to access and download sensitive files from the web server, such as configuration files containing database credentials or site backups. This could lead to a full compromise of the website and its data.

Technical details

A Path Traversal vulnerability (CWE-22) exists in the WPMU DEV Forminator plugin for WordPress through version 1.55.0.2. The flaw stems from improper limitation of pathnames, which allows an unauthenticated remote attacker to perform arbitrary file downloads via specially crafted requests. By exploiting this, an attacker can read sensitive system files, including wp-config.php or other internal data, without any prior authentication or user interaction. The issue is resolved in version 1.55.1.

Affected products

  • WPMU DEV Forminator <= 1.55.0.2

Timeline

  • 2026-06-23: disclosed: Reported by researcher daroo
  • 2026-07-08: advisory: Patchstack published advisory
  • 2026-07-13: advisory: NVD published CVE record
  • patched: Fixed in version 1.55.1

References

Related threats