top of page
perceptive_background_267k.jpg

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/att…

Published:

31 juli 2026 om 22:00:00

Alert date:

1 augustus 2026 om 07:00:32

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Zero-Day Vulnerabilities

The FormGent plugin for WordPress (versions up to and including 1.9.2) contains a critical vulnerability allowing unauthenticated arbitrary file deletion via the /wp-json/formgent/responses/attachments REST API endpoint. The flaw stems from a missing capability check and lack of authentication middleware in the REST API route registration. Attackers can delete files within the formgent uploads directory without any credentials. On Linux servers where the wp-content/uploads/formgent directory does not yet exist, path traversal protections can be bypassed entirely. This bypass enables deletion of critical files such as wp-config.php, potentially leading to complete site takeover by triggering a fresh WordPress installation. The vulnerability is especially dangerous for newly installed instances of the plugin. A patch was introduced in version 1.10.0.

Technical details

Mitigation steps:

Affected products:

FormGent WordPress Plugin (versions up to 1.9.2)

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page