WP Clinic
Entrar Registrarse

SEGURIDAD DE PLUGINS

¿Es seguro FormGent?

AI-powered form builder that’s built for performance, simplicity, and feels like a part of WordPress, not a separate platform.

Qué hace este plugin

  • Slug: formgent
  • Autor: wpWax
  • 1000+ instalaciones activas
  • 88/100 calificación (7 reseñas en wordpress.org)
  • 37642 descargas totales
  • En WordPress.org desde 2024-10-20

conversational formform buildermultistep formpayment formsurvey

Estado de mantenimiento

  • Última actualización: 2026-07-13 5:25pm GMT
  • Probado hasta WordPress: 7.0.2
  • Requiere PHP: 7.4+

Vulnerabilidades conocidas

1 CVE conocido registrado para FormGent. Reportadas entre 2025 y 2026.

CVE Vulnerabilidad Tipo Gravedad Afectadas Corregido en Publicado Estado
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] <= 1.8.1 (unfixed) Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) Alta 8,6 < 1.8.1 1.8.1 2026-03-03
CVE-2025-10916 FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.0.4 Control externo del nombre o la ruta de un archivo Crítica 9,1 < 1.0.4 1.0.4 2025-09-30

FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] <= 1.8.1 (unfixed)

The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

CVE-2025-10916

The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp-json/formgent/responses/attachments REST endpoint in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Descripción técnica mostrada en el idioma original de la fuente (inglés).

Fuente: Wordfence

Cómo solucionarlo

Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.

Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.

Alternativas más seguras / más establecidas

Verifica tu propio sitio WordPress

Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.