SecurityWeek Follow 300,000 WordPress Sites Potentially Exposed to Hacking Due to Form Plugin Flaw Tracked as CVE-2026-15748, the arbitrary file upload bug allows unauthenticated attackers to upload executable files. https://www.securityweek.com/300000-wordpress-sites-potentially-exposed-to-hacking-due-to-form-plugin-flaw/ securityweek.com