Recursos /
Plugins de WordPress /
FormGent
SEGURIDAD DE PLUGINS
¿Es seguro FormGent?
AI-powered form builder that’s built for performance, simplicity, and feels like a part of WordPress, not a separate platform.
Qué hace este plugin
- Slug:
formgent
- Autor: wpWax
- 1000+ instalaciones activas
- 88/100 calificación (7 reseñas en wordpress.org)
- 37642 descargas totales
- En WordPress.org desde 2024-10-20
conversational formform buildermultistep formpayment formsurvey
Estado de mantenimiento
- Última actualización: 2026-07-13 5:25pm GMT
- Probado hasta WordPress: 7.0.2
- Requiere PHP: 7.4+
Vulnerabilidades conocidas
1 CVE conocido registrado para FormGent.
Reportadas entre 2025 y 2026.
| CVE |
Vulnerabilidad |
Tipo |
Gravedad |
Afectadas |
Corregido en |
Publicado |
Estado |
|
—
|
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] <= 1.8.1 (unfixed) |
Limitación incorrecta de una ruta a un directorio restringido (Path Traversal) |
Alta
8,6
|
< 1.8.1
|
1.8.1 |
2026-03-03 |
—
|
|
CVE-2025-10916
|
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.0.4 |
Control externo del nombre o la ruta de un archivo |
Crítica
9,1
|
< 1.0.4
|
1.0.4 |
2025-09-30 |
—
|
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] <= 1.8.1 (unfixed)
The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
CVE-2025-10916
The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp-json/formgent/responses/attachments REST endpoint in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Descripción técnica mostrada en el idioma original de la fuente (inglés).
Fuente:
Wordfence
Cómo solucionarlo
Actualiza este plugin a la última versión de wordpress.org — cada CVE de arriba indica la versión exacta que lo corrigió ("Corregido en") cuando hay una registrada.
Este es el historial completo de vulnerabilidades conocidas del plugin, no un escaneo de una instalación específica — ejecuta un escaneo gratis de tu propio sitio para verificar tu versión instalada exacta.
Alternativas más seguras / más establecidas
-
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More
— 5000000+ instalaciones activas
— 96/100 (14356)
-
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
— 700000+ instalaciones activas
— 96/100 (780)
— PHP máx. <8.0
-
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
— 600000+ instalaciones activas
— 94/100 (500)
— PHP máx. 8.4
-
Ninja Forms – The Contact Form Builder That Grows With You
— 600000+ instalaciones activas
— 88/100 (1394)
-
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz
— 500000+ instalaciones activas
— 98/100 (83)
Verifica tu propio sitio WordPress
Ejecuta un escaneo pasivo gratis ahora, o crea una cuenta gratuita e instala el plugin de WP Clinic para un escaneo profundo de toda tu cuenta de hosting y reparación asistida por IA.