WordPress Plugin Vulnerabilities

Forminator Forms < 1.56.2 - Unauthenticated Arbitrary File Upload via Forged Upload Field Configuration

Description

The plugin is vulnerable to Arbitrary File Upload via the handle_file_upload function, due to insufficient file type validation, where the dangerous-extension blocklist performs exact-key matching that is bypassed by pipe-alternative MIME type keys, combined with a public submission handler that trusts attacker-controlled upload field configuration injected via a forged Select field value. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible.

Affects Plugins

Fixed in 1.56.2

References

Miscellaneous

Original Researcher
daroo
Verified
No

Timeline

Publicly Published
2026-08-17 (about 1 month ago)
Added
2026-08-18 (about 1 month ago)
Last Updated
2026-10-01 (about 8 hours ago)

Other