A security vulnerability has been found in the Forminator Forms plugin for WordPress, affecting all versions up to and including 1.56.1. The flaw exists in the plugin's public form file upload feature, which fails to properly check what type of files users are trying to upload.
Because of this gap, unauthenticated attackers (people who do not have login access to your WordPress dashboard) can bypass the plugin's file type restrictions to upload dangerous, executable files to your site. If these files are uploaded successfully, attackers could run unauthorized code on your website, which may let them take full control of your site, steal sensitive information, alter your site's content, or harm visitors who access your site.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-15748