Summary
CVE-2026-57815 is a high-severity Path Traversal (CWE-22) vulnerability in the Forminator WordPress plugin by WPMU DEV, affecting all versions up to and including 1.55.0.2. The flaw allows unauthenticated remote attackers to read and download arbitrary files from the affected web server — including files containing login credentials and backup data — with no authentication or user interaction required. The CVSS v3.1 base score is 7.5 (High).
Technical details
- Root cause: Improper limitation of a pathname to a restricted directory within the Forminator plugin, enabling requests to traverse outside the intended file path boundary.
- Trigger conditions: The vulnerability is exploitable remotely over the network with no authentication and no user interaction required (AV:N/AC:L/PR:N/UI:N).
- Attack vector: A remote, unauthenticated attacker can send a crafted HTTP request to the affected WordPress installation to reference files outside the webroot or permitted plugin directories.
- Impact: Arbitrary file download from the server. Exploitable files include those containing login credentials, configuration data, and backup archives — enabling sensitive information disclosure and potential escalation to further compromise.
- Exploitation outlook: The vulnerability is considered highly dangerous and anticipated for use in mass-exploitation campaigns targeting internet-facing WordPress sites at scale.
Affected software
- Forminator (WordPress plugin by WPMU DEV): all versions from initial release through 1.55.0.2 (inclusive)
Severity
- CVSS v3.1 Base Score: 7.5 (High)
- Vector:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate: Update the Forminator plugin to version 1.55.1 or later, which contains the vendor-supplied fix.
- If patching is not immediately possible: Consider temporarily deactivating the Forminator plugin on internet-facing WordPress installations until the update can be applied, and review server-side access logs for anomalous file-read requests.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

