WP Clinic
Entrar Registrarse

CVE · Critical

CVE-2025-10916 — FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.0.4

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
CVE-2025-10916 FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.0.4 Control externo del nombre o la ruta de un archivo Crítica 9,1 < 1.0.4 1.0.4 2025-09-30

CVE-2025-10916

The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp-json/formgent/responses/attachments REST endpoint in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Escanea tu sitio WordPress gratis

Sin registro, sin tarjeta de crédito — ingresa tu URL y obtén un informe de seguridad en segundos.