WPMU DEV A.I CyberSecurity Scoring
WPMU DEV
Company Information
Website:http://wpmudev.com
Employees number:137
Number of followers:18,082
NAICS:513
Industry Type:Technology, Information and Internet
Homepage:wpmudev.com
WPMU DEV Risk Score (AI oriented)
Between 750 and 799
WPMU DEVTechnology, Information and Internet
Updated:
18/08/2026
18/08/2026
750/1000
Fair
Baa
WPMU DEV Global Score (TPRM)
xxxx
WPMU DEVTechnology, Information and Internet
Score locked

WPMU DEVFair
Current Score
750Baa (FAIR)
01000
1 incidents
-17 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
AUGUST 2026
750
JULY 2026
767
Vulnerability
14 Jul 2026 • WPMU DEV
WordPress Sites Using Forminator Forms and Forminator Forms: Critical WordPress Plugin Vulnerability Exposes 600,000 Sites to File Upload Attacks
Critical Vulnerability in Forminator Forms WordPress Plugin Exposes 600,000+ Sites to Remote Takeover
750
CRITICAL-17
WPM1787049574
Critical Vulnerability in Forminator Forms WordPress Plugin Exposes 600,000+ Sites to Remote Takeover
A severe security flaw in the Forminator Forms WordPress plugin (CVE-2026-15748, CVSS 9.8) allows unauthenticated attackers to upload malicious PHP files, potentially leading to full website compromise. The vulnerability affects versions 1.56.1 and earlier of the plugin, which is used by over 600,000 active installations for building forms, polls, quizzes, and payment systems.
Discovered by security researcher daroo through the Wordfence bug bounty program, the flaw was reported and validated on July 14, 2026. The vendor released a patch in Forminator Forms version 1.56.2 on July 31, 2026.
The exploit stems from improper file-upload handling, where attackers can forge upload configurations via the plugin’s Select field. By manipulating values such as the field name, type, and file settings, malicious requests bypass the plugin’s blocklist-based extension filtering. For example, using ph(p) instead of the blocked php extension evades detection, as WordPress still interprets it as a valid PHP file.
While uploaded files are typically stored in a directory protected by .htaccess rules, sites with custom upload paths may lack this safeguard. If a PHP file lands in an executable, web-accessible location, attackers can trigger remote code execution (RCE), deploy webshells, steal credentials, or gain full control of the site.
Administrators are urged to update to the latest version and audit form configurations, upload directories, and server-side execution permissions.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JUNE 2026
767
MAY 2026
767
APRIL 2026
767
MARCH 2026
767
FEBRUARY 2026
767
JANUARY 2026
767
DECEMBER 2025
767
NOVEMBER 2025
767
OCTOBER 2025
767
SEPTEMBER 2025
767
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for WPMU DEV ??
What was WPMU DEV's A.I Rankiteo Cyber Score in July 2026 ??
What was WPMU DEV's A.I Rankiteo Cyber Score in June 2026 ??
What was WPMU DEV's A.I Rankiteo Cyber Score in May 2026 ??
What was WPMU DEV's A.I Rankiteo Cyber Score in April 2026 ??
What was WPMU DEV's A.I Rankiteo Cyber Score in March 2026 ??
What was WPMU DEV's A.I Rankiteo Cyber Score in February 2026 ??
What was WPMU DEV's A.I Rankiteo Cyber Score in January 2026 ??
What was WPMU DEV's A.I Rankiteo Cyber Score in December 2025 ??
What was WPMU DEV's A.I Rankiteo Cyber Score in November 2025 ??
What was WPMU DEV's A.I Rankiteo Cyber Score in October 2025 ??
What was WPMU DEV's A.I Rankiteo Cyber Score in September 2025 ??
What is the average per-incident point impact on WPMU DEV's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with WPMU DEV ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view WPMU DEV's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?