WP Clinic
Log in Sign up

PLUGIN SECURITY

Is FormGent safe?

AI-powered form builder that’s built for performance, simplicity, and feels like a part of WordPress, not a separate platform.

What this plugin does

  • Slug: formgent
  • Author: wpWax
  • 1000+ active installs
  • 88/100 rating (7 reviews on wordpress.org)
  • 37642 all-time downloads
  • On WordPress.org since 2024-10-20

conversational formform buildermultistep formpayment formsurvey

Maintenance status

  • Last updated: 2026-07-13 5:25pm GMT
  • Tested up to WordPress: 7.0.2
  • Requires PHP: 7.4+

Known vulnerabilities

1 known CVE on file for FormGent. Reported between 2025 and 2026.

CVE Vulnerability Type Severity Affected Fixed in Published Status
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] <= 1.8.1 (unfixed) Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') High 8.6 < 1.8.1 1.8.1 2026-03-03
CVE-2025-10916 FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.0.4 External Control of File Name or Path Critical 9.1 < 1.0.4 1.0.4 2025-09-30

FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] <= 1.8.1 (unfixed)

The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Source: Wordfence

CVE-2025-10916

The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp-json/formgent/responses/attachments REST endpoint in all versions up to, and including, 1.0.3. This makes it possible for unauthenticated attackers to delete arbitrary files on the server, which can easily lead to remote code execution when the right file is deleted (such as wp-config.php).

Source: Wordfence

How to fix it

Update this plugin to the latest release from wordpress.org — each CVE above lists the exact release that fixed it ("Fixed in") when one is on file.

This is the plugin's full known vulnerability history, not a scan of any specific installation — run a free scan of your own site to check your exact installed version.

Safer / more established alternatives

Check your own WordPress site

Run a free passive scan now, or create a free account and install the WP Clinic plugin for a deep scan of your whole hosting account and AI-assisted repair.