CVE · High

CVE-2025-15028 — FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.10.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2025-15028 FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.10.0 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') High 7.2 < 1.10.0 1.10.0 2026-08-05

CVE-2025-15028

The FormGent plugin's handling of form submission fields is flawed, allowing malicious code to be embedded within the plugin's functionality. This weakness can be exploited by unauthorized parties who can then have their own JavaScript executed on vulnerable sites when visited by users, without needing prior authentication or authorization. The issue affects all versions of the plugin up through 1.9.2.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.