Unauthorized File Deletion Vulnerability in FormGent Plugin for WordPress
CVE-2026-3141

9.1CRITICAL

What is CVE-2026-3141?

The FormGent plugin for WordPress exhibits a significant security vulnerability that allows unauthenticated attackers to delete arbitrary files from the server. This issue arises from a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to and including 1.9.2. The vulnerability is exacerbated by the lack of authentication middleware in the API routes, which permits unauthorized access to sensitive file operations. Particularly on Linux servers without the wp-content/uploads/formgent directory, attackers can bypass path traversal protections, facilitating the deletion of crucial files such as wp-config.php, leading to potential complete site compromise.

Affected Version(s)

FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More 0 <= 1.9.2

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Athiwat Tiprasaharn (Jitlada)
Itthidej Aramsri (Boeing777)
.