CVE Database /
CVE-2026-3141
CVE · Critical
CVE-2026-3141 — FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.10.0
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
CVE-2026-3141
|
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.10.0 |
Missing Authorization |
Critical
9.1
|
< 1.10.0
|
1.10.0 |
2026-03-03 |
—
|
CVE-2026-3141
The FormGent plugin for WordPress has a security flaw that allows unauthorized users to delete any file on the server. This is because the plugin's REST API endpoint for handling form attachments doesn't require authentication, allowing anyone to access and delete files. In some cases, this vulnerability can be exploited to delete sensitive files like the WordPress configuration file, potentially allowing an attacker to take full control of the site.
Based on public CVE data (MITRE/NVD).
Scan your WordPress site free
No signup, no credit card — enter your URL and get a security report in seconds.
See the full security page for this plugin
Browse the CVE database
Browse all security findings