top of page
perceptive_background_267k.jpg

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/att…

Published:

1 August 2026 at 00:00:00

Alert date:

1 August 2026 at 09:00:32

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

The FormGent plugin for WordPress (versions up to and including 1.9.2) contains a critical vulnerability allowing unauthenticated arbitrary file deletion via the /wp-json/formgent/responses/attachments REST API endpoint. The flaw stems from a missing capability check and lack of authentication middleware in the REST API route registration. Attackers can delete files within the formgent uploads directory without any credentials. On Linux servers where the wp-content/uploads/formgent directory does not yet exist, path traversal protections can be bypassed entirely. This bypass enables deletion of critical files such as wp-config.php, potentially leading to complete site takeover by triggering a fresh WordPress installation. The vulnerability is especially dangerous for newly installed instances of the plugin. A patch was introduced in version 1.10.0.

Technical details

Mitigation steps:

Affected products:

FormGent WordPress Plugin (versions up to 1.9.2)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page