Sploitus

Exploit for CVE-2026-15748

githubexploit Β· 2026-08-18

Exploit Code

README32 lines
## https://sploitus.com/exploit?id=37A2BF9F-33E3-593D-89A3-A9A51C4AC0C3
# CVE-2026-15748 - Forminator Forms Unauthenticated RCE

> **Crafted by Yora**  
> FOR EDUCATIONAL & AUTHORIZED TESTING ONLY

## πŸ“Œ Deskripsi

CVE-2026-15748 adalah kerentanan **Unauthenticated Remote Code Execution (RCE)** pada plugin **Forminator** untuk WordPress. Plugin ini digunakan di lebih dari **600.000 situs** dan rentan pada versi **≀ 1.56.1**.

Kerentanan ini memungkinkan attacker untuk **upload file PHP** dan mengeksekusi kode di server target **tanpa perlu login**, dengan syarat target memiliki form yang memiliki **File Upload** dan **Select Field** secara bersamaan.

## πŸ”₯ Fitur Tool

- βœ… Deteksi WordPress & Forminator
- βœ… Deteksi versi Forminator (5 metode)
- βœ… Identifikasi target vulnerable (≀ 1.56.1)
- βœ… **Deep crawl** – sitemap, internal links, 20+ common paths
- βœ… Deteksi form dengan **file upload + select field**
- βœ… **Ekstrak nonce** otomatis
- βœ… **Upload test** (file .txt) untuk verifikasi
- βœ… Output detail per target (versi, status, upload result)
- βœ… Multi-threading support
- βœ… WAF-friendly (delay, user-agent rotation)

## πŸ“¦ Instalasi

### 1. Clone Repository

```bash
git clone https://github.com/yora/cve-2026-15748.git
cd cve-2026-15748