CVE-2026-15748 is a critical vulnerability in the Forminator WordPress plugin (versions up to and including 1.56.1) that allows unauthenticated attackers to upload arbitrary files, including PHP shells, leading to remote code execution. The flaw is due to insufficient file type validation in the handle_file_upload() function, which can be bypassed using pipe-alternative MIME type keys. Patched in version 1.56.2.