Unauthorized File Deletion Vulnerability in FormGent Plugin for WordPress
CVE-2026-3141
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 August 2026
What is CVE-2026-3141?
The FormGent plugin for WordPress exhibits a significant security vulnerability that allows unauthenticated attackers to delete arbitrary files from the server. This issue arises from a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to and including 1.9.2. The vulnerability is exacerbated by the lack of authentication middleware in the API routes, which permits unauthorized access to sensitive file operations. Particularly on Linux servers without the wp-content/uploads/formgent directory, attackers can bypass path traversal protections, facilitating the deletion of crucial files such as wp-config.php, leading to potential complete site compromise.
Affected Version(s)
FormGent β Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More 0 <= 1.9.2
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved