600,000 WordPress Sites Affected by Arbitrary File Upload Vulnerability in Forminator Forms WordPress Plugin
Brief
On July 14th, 2026, we received a submission for an Unauthenticated Arbitrary File Upload vulnerability in Forminator Forms , a WordPress plugin with more than 600,000 active installations. This vulnerability makes it possible for unauthenticated attackers to upload arbitrary files, including executable PHP files, to a vulnerable site, which can lead to remote code execution and complete site compromise.
The vulnerability is only exploitable on sites that have a form containing both a File Upload field and a Select field.
Props to daroo who discovered and responsibly reported this vulnerability through the Wordfence Bug Bounty Program . This researcher earned a bounty of $2,048. 00 for this discovery.
