Resources /
WordPress Plugins /
FormGent
PLUGIN SECURITY
Is FormGent safe?
AI-powered form builder that’s built for performance, simplicity, and feels like a part of WordPress, not a separate platform.
What this plugin does
- Slug:
formgent
- Author: wpWax
- 1000+ active installs
- 88/100 rating (7 reviews on wordpress.org)
- 37642 all-time downloads
- On WordPress.org since 2024-10-20
conversational formform buildermultistep formpayment formsurvey
Maintenance status
- Last updated: 2026-07-13 5:25pm GMT
- Tested up to WordPress: 7.0.2
- Requires PHP: 7.4+
Known vulnerabilities
1 known CVE on file for FormGent.
Reported between 2025 and 2026.
| CVE |
Vulnerability |
Type |
Severity |
Affected |
Fixed in |
Published |
Status |
|
—
|
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] <= 1.8.1 (unfixed) |
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') |
High
8.6
|
< 1.8.1
|
1.8.1 |
2026-03-03 |
—
|
|
CVE-2025-10916
|
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.0.4 |
External Control of File Name or Path |
Critical
9.1
|
< 1.0.4
|
1.0.4 |
2025-09-30 |
—
|
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] <= 1.8.1 (unfixed)
The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Source:
Wordfence
CVE-2025-10916
The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp-json/formgent/responses/attachments REST endpoint in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).
Source:
Wordfence
How to fix it
Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.
This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.
Safer / more established alternatives
-
WPForms – AI Form Builder for WordPress – Contact Forms, Payment Forms, Survey Form, Quiz & More
— 5000000+ active installs
— 96/100 (14356)
-
Fluent Forms – Customizable Contact Forms, Survey, Quiz, & Conversational Form Builder
— 700000+ active installs
— 96/100 (780)
— max PHP <8.0
-
MetForm – Contact Form, Survey, Quiz, & Custom Form Builder for Elementor
— 600000+ active installs
— 94/100 (500)
— max PHP 8.4
-
Ninja Forms – The Contact Form Builder That Grows With You
— 600000+ active installs
— 88/100 (1394)
-
SureForms – Contact Form Builder, AI Forms, Payment Form, Survey & Quiz
— 500000+ active installs
— 98/100 (83)
Check your own WordPress site
Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.