
Critical File Upload Flaw Exposes 600,000 WordPress Sites Using Forminator Plugin
An unauthenticated attacker can upload arbitrary files to WordPress sites running Forminator Forms, affecting over 600,000 installations. Immediate updates are recommended.
A serious security vulnerability has been disclosed in Forminator Forms, a widely used WordPress plugin that powers contact forms, quizzes, and polls on more than 600,000 websites. The flaw allows an attacker with no account or login credentials to upload arbitrary files to the server, which can lead to remote code execution, site defacement, data theft, or the installation of persistent backdoors. The vulnerability was submitted to the Wordfence team on July 14th, 2026, and has since been coordinated with the plugin developers.
WordPress plugins are add-on software that extend the core WordPress platform. Forminator Forms is one of the most popular form-building plugins, used by site owners to create everything from simple contact forms to complex calculators and file upload fields. Because the plugin is so prevalent, the exposure is significant: any site running a vulnerable version of Forminator Forms is potentially at risk, even if the site administrator has never thought about security.
The vulnerability is classified as an unauthenticated arbitrary file upload. "Unauthenticated" means the attacker does not need to log in or possess any credentials to exploit the flaw. "Arbitrary file upload" means the attacker can upload any type of file they choose, including scripts that can execute on the server. In many cases, this is a stepping stone to a full website takeover. An attacker could upload a web shell, a type of malicious script that provides a remote control panel, allowing them to modify files, steal data, or use the site to distribute malware to visitors.
WordPress file upload vulnerabilities are particularly dangerous because WordPress and its plugins are written in PHP, a programming language that runs on web servers. When an attacker uploads a file with PHP code, the server can execute that code, giving the attacker the same privileges as the legitimate owner. This allows them to bypass nearly every security control, including firewalls and access controls.
The exact technical details of how the flaw works have not been fully disclosed, but the file upload functionality in Forminator Forms is the likely target. The plugin includes a file upload field for users to attach files when submitting a form. The vulnerability likely stems from insufficient validation of file types or file names, allowing an attacker to disguise malicious executable code as a benign file and upload it to the server. Once the file is on the server, it can be triggered by a direct request or by other means, depending on the specific code path.
Site owners who use Forminator Forms should treat this as an emergency. The first step is to check the installed version of the plugin and update it to the latest available version as soon as possible. WordPress administrators can update plugins from the Dashboard, but it is wise to confirm that the plugin actually needs the update by checking the WordPress admin area for notifications. If the plugin is no longer in use, it should be removed entirely. Many successful attacks occur because site owners forget about old plugins that remain installed but unused.
Beyond the update, site owners should look for signs of compromise. If a web shell has been uploaded, it may appear as an unfamiliar file with a funny name in the uploads directory or elsewhere. Checking for unexpected files and monitoring server logs for suspicious requests can help identify an ongoing attack. Since file upload vulnerabilities can be used to upload backdoors, a thorough scan of the website files is recommended after updating.
For those running WordPress on unmanaged hosting, the responsibility falls on the site owner to keep plugins updated. For website owners and IT teams who want an extra layer of protection, AEU Hosting offers managed WordPress hosting, which is secured end to end, meaning many routine security maintenance tasks are handled for you, including keeping the platform and its plugins patched. This can significantly reduce the risk of falling victim to vulnerabilities such as this one.
Independent security researchers and the security community play a vital role in finding and reporting these flaws before they are exploited. The submission to Wordfence highlights the importance of coordinated disclosure. Plugin developers and security vendors work together to release patches and inform users, allowing them to protect their websites before attackers can use the exploit.
In the meantime, site owners should rely on best practices. Use reputable security plugins, enable automatic updates for plugins and themes, and take regular backups so that a site can be restored quickly if something goes wrong. Remember that no security measure is foolproof, but staying current with updates is one of the most effective and simplest ways to close known vulnerabilities.
While the specific version numbers and patch details have not been fully released, it is clear that action must be taken immediately. The existence of the vulnerability itself is a serious concern, but if it is actively exploited, the consequences for site owners and their visitors could be severe, including data loss and compromised user information. Therefore, all site administrators should check their Forminator Forms installation and update it without delay.
Finally, understanding that vulnerabilities like these are common should not lead to panic, but to vigilance. The WordPress ecosystem is massive, and plugins are a common attack surface. By staying informed, applying updates promptly, and choosing a hosting provider that prioritizes security, website owners can significantly lower their risk. AEU Hosting, with its managed WordPress hosting approach, is one such option for those who prefer a security-first environment.
In summary, the unauthenticated arbitrary file upload vulnerability in Forminator Forms is a critical security risk affecting a large number of WordPress sites. Update your Forminator Forms plugin now, scan for signs of attack, and remember that proactive security measures are your most reliable defense.
How to Protect Yourself
- Update the Forminator Forms plugin to the newest version right away by going to your WordPress dashboard, clicking Plugins, and hitting the update link if one is available.
- If you do not use Forminator Forms, you can remove the plugin entirely from your site to avoid any risk.
- Turn on automatic updates for your WordPress plugins so this kind of problem gets fixed without you having to remember to do it.
- Make a full backup of your website before making any changes, so you can restore it if something goes wrong.
- Watch your website's file directory for any files you do not recognize, and remove them if you find one.
- Use a security plugin or a managed WordPress hosting service that monitors your site and helps keep plugins updated for you.