


Perceptive Security
SOC/SIEM Consultancy

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/att…
Published:
31 juli 2026 om 22:00:00
Alert date:
1 augustus 2026 om 07:00:32
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
The FormGent plugin for WordPress (versions up to and including 1.9.2) contains a critical vulnerability allowing unauthenticated arbitrary file deletion via the /wp-json/formgent/responses/attachments REST API endpoint. The flaw stems from a missing capability check and lack of authentication middleware in the REST API route registration. Attackers can delete files within the formgent uploads directory without any credentials. On Linux servers where the wp-content/uploads/formgent directory does not yet exist, path traversal protections can be bypassed entirely. This bypass enables deletion of critical files such as wp-config.php, potentially leading to complete site takeover by triggering a fresh WordPress installation. The vulnerability is especially dangerous for newly installed instances of the plugin. A patch was introduced in version 1.10.0.
Technical details
Mitigation steps:
Affected products:
FormGent WordPress Plugin (versions up to 1.9.2)
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-3141
https://plugins.trac.wordpress.org/browser/formgent/tags/1.3.1/app/Http/Controllers/AttachmentController.php#L59
https://plugins.trac.wordpress.org/browser/formgent/tags/1.3.1/routes/rest/api.php#L27
https://plugins.trac.wordpress.org/browser/formgent/trunk/app/Http/Controllers/AttachmentController.php#L59
https://plugins.trac.wordpress.org/browser/formgent/trunk/routes/rest/api.php#L27
https://plugins.trac.wordpress.org/changeset/3604540/formgent/trunk/app/Http/Controllers/AttachmentController.php
https://plugins.trac.wordpress.org/changeset?old_path=%2Fformgent/tags/1.9.2&new_path=%2Fformgent/tags/1.10.0
https://www.wordfence.com/threat-intel/vulnerabilities/id/097a9d0f-fa38-4fdc-9048-43dd65e7652c?source=cve
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
