The Forminator plugin for WordPress is vulnerable to a security issue that allows unauthorized users with administrator-level access or above to upload files to the affected website’s server. This vulnerability affects all versions up to 1.27.0. Even though files can be uploaded, the server is configured in such a way that code cannot be executed from these files.