CVE · Critical

CVE-2026-3141 — FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.10.0

CVE Vulnerability Type Severity Affected Fixed in Published Status
CVE-2026-3141 FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.10.0 Missing Authorization Critical 9.1 < 1.10.0 1.10.0 2026-03-03

CVE-2026-3141

The FormGent plugin for WordPress has a security flaw that allows unauthorized users to delete any file on the server. This is because the plugin's REST API endpoint for handling form attachments doesn't require authentication, allowing anyone to access and delete files. In some cases, this vulnerability can be exploited to delete sensitive files like the WordPress configuration file, potentially allowing an attacker to take full control of the site.

Based on public CVE data (MITRE/NVD).

Scan your WordPress site free

No signup, no credit card — enter your URL and get a security report in seconds.