{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/formidable-charts/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-15990"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Formidable Charts"],"_cs_severities":["high"],"_cs_tags":["vulnerability","wordpress","web-application"],"_cs_type":"advisory","_cs_vendors":["Formidable Forms"],"content_html":"\u003cp\u003eThe Formidable Charts plugin for WordPress (versions 2.0.1 and below) contains a directory traversal vulnerability. An unauthenticated attacker can exploit this flaw by manipulating the 'frm_graph' parameter in HTTP requests. Successful exploitation allows for the reading of arbitrary files from the server filesystem, which may lead to the disclosure of sensitive configuration files, credentials, or application data.\u003c/p\u003e\n\u003cp\u003eThe vulnerability is conditional: it requires Formidable Forms Lite, Formidable Forms Pro, and Formidable Charts to be active on the target site. Furthermore, the directory 'wp-content/uploads/frm-charts/' must exist, which typically occurs after the application renders an image-format chart. This vulnerability poses a significant risk to the confidentiality of the web server, particularly in environments hosting sensitive data or configuration files in the web root or accessible directories.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in unauthorized access to arbitrary files on the host server. Depending on the target environment, this could lead to the exfiltration of sensitive information, such as wp-config.php files containing database credentials, API keys, or other environmental configuration data. This could facilitate further exploitation, privilege escalation, or full site takeover.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Formidable Charts plugin to the latest version immediately to remediate CVE-2026-15990.\u003c/li\u003e\n\u003cli\u003eMonitor web access logs for suspicious patterns in the 'frm_graph' parameter, specifically looking for sequences indicative of path traversal (e.g., '../', '..%2f').\u003c/li\u003e\n\u003cli\u003eRestrict web server permissions to ensure that the WordPress application user has only the minimum necessary read access to the filesystem.\u003c/li\u003e\n\u003cli\u003eDeploy a web application firewall (WAF) rule to inspect and block requests containing traversal sequences targeting the WordPress uploads directory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-26T16:21:42Z","date_published":"2026-08-26T16:21:42Z","id":"https://feed.craftedsignal.io/briefs/2026-08-formidable-charts-traversal/","summary":"The Formidable Charts WordPress plugin is vulnerable to an unauthenticated directory traversal attack via the 'frm_graph' parameter, enabling arbitrary file read on the underlying server.","title":"CVE-2026-15990 Directory Traversal in Formidable Charts Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-formidable-charts-traversal/"}],"language":"en","title":"CraftedSignal Threat Feed - Formidable Charts","version":"https://jsonfeed.org/version/1.1"}