CVE Database /
CVE-2025-10916
CVE · Critical
CVE-2025-10916 — FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.0.4
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2025-10916
|
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.0.4 |
External Control of File Name or Path |
Critical
9.1
|
< 1.0.4
|
1.0.4 |
2025-09-30 |
—
|
CVE-2025-10916
The FormGent plugin for WordPress contains a flaw in its REST endpoint handling that allows unauthorized access to delete any file on the server. This vulnerability affects all versions up to and including 1.0.3, enabling an unauthenticated attacker to potentially trigger remote code execution by deleting specific files like wp-config.php.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings