Forminator Forms
BitFire blocks automated Forminator submission exploits and uses PRO RASP to prevent CVE-2026-15748 from creating unauthorized PHP files.
- Affected sites
- 600,000+
- Attack class
- Arbitrary File Upload
Review the attack behind each advisory and the BitFire control—bot protection, WAF, or runtime RASP—that prevents it from becoming a compromise.
Showing 1–6 of 12 records · Updated September 4, 2026
BitFire blocks automated Forminator submission exploits and uses PRO RASP to prevent CVE-2026-15748 from creating unauthorized PHP files.
BitFire RASP blocks CVE-2026-14488 at the database layer by preventing users without the required WordPress capabilities from deleting posts and pages.
BitFire blocks CVE-2026-63030 with verified-browser POST protection, SQL injection detection, and RASP prevention of administrator account creation.
Profile Builder could turn a failed registration into an administrator autologin link, while BitFire authentication RASP prevents unauthenticated requests from minting WordPress auth cookies.
BitFire blocks automated CVE-2026-5524 upload requests and uses PRO RASP to prevent Divi Form Builder from creating unauthorized executable PHP files.
BitFire blocks automated exploit requests and uses PRO RASP to prevent CVE-2026-15158 from creating an unauthorized PHP file through Blocksy Companion Pro.
Page 1 of 2
BitFire combines bot controls, request inspection, and runtime enforcement so emerging vulnerabilities fail before a CVE-specific rule exists.