The Forminator plugin for WordPress is vulnerable to having malicious files uploaded to the affected website’s server. This is because the plugin doesn’t properly check what type of file is being uploaded before it is accepted. This makes it possible for anyone, even those not logged in, to upload malicious files, which may allow them to execute code on the server. Versions of the plugin up to and including 1.24.6 are affected.