If your business website runs on WordPress, a newly disclosed security flaw is worth pausing for. Researchers have revealed a critical vulnerability in Forminator Forms, a plugin installed on more than 600,000 websites, that could let an attacker take complete control of a site without even needing a username or password. For small businesses across Gippsland and regional Victoria who rely on their website to take bookings, capture leads, or process customer enquiries, this is exactly the kind of quiet, unglamorous vulnerability that ends up doing real damage.
As reported by The Hacker News, the flaw – tracked as CVE-2026-15748 and rated 9.8 out of 10 in severity – allows an attacker to upload malicious PHP files through the Forminator plugin’s file upload feature. Because the flaw doesn’t require the attacker to be logged in, anyone who finds a vulnerable site can potentially exploit it directly. Once a malicious file is uploaded and executed, the attacker effectively has the same level of control over the website as the site owner does.
Forminator is a popular tool for building contact forms, quote request forms, polls, and quizzes on WordPress sites. It’s the kind of plugin many small businesses install once, set up, and then forget about entirely – which is exactly the problem.
It’s tempting to read stories like this and assume they only affect large corporations with dedicated IT security teams. In reality, small business websites are often easier targets precisely because nobody is actively watching them. A compromised site can be used to:
For a local trade business, retailer, clinic, or professional service, even a few days of a defaced or blacklisted website can mean lost bookings, lost sales, and an awkward conversation with customers about why their details might have been exposed.
WordPress itself is generally well maintained and secure. The bigger risk almost always comes from the plugins and themes installed on top of it – and most small business websites are running far more of these than the owner realises, often installed years ago by a web designer who has long since moved on. Every plugin is a piece of software that needs updating, and every outdated plugin is a potential unlocked door.
This particular Forminator vulnerability is a useful case study because it shows how quickly a “set and forget” plugin can become a serious liability. The plugin developer has released a patch, but a patch only protects you if it’s actually applied.
This won’t be the last plugin vulnerability to make headlines, and it’s unlikely to be the most severe one your business ever encounters. The businesses that come through these events unscathed are the ones with a simple, ongoing maintenance routine rather than those relying on luck.
You don’t need to be technical to get a basic sense of your exposure. Log into your WordPress admin dashboard, go to the Plugins section, and look at two things: how many plugins are installed, and whether any are flagged as needing an update. If you don’t have a login, or you’re not sure who does, that in itself is a sign your website’s security is being managed by nobody – which is worth fixing regardless of this particular vulnerability.
Website security rarely feels urgent until the moment it becomes very urgent indeed. A ten-minute plugin update today is a much better use of your time than a weekend spent explaining to customers why your site was serving malware.
If you’re not sure whether your business is exposed to this kind of risk, Maximum IT Solutions offers a free security assessment for businesses across Gippsland and regional Victoria. We’ll review your current setup and flag anything that needs urgent attention — no obligation.
(+61) 0412 440 804