FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting
high
The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission fields in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for...
- CVSS:
- 7.2
- Affected:
- up to 1.9.2
- Fixed in:
- 1.10.0
- Disclosed:
- Aug 5, 2026
CVE-2025-15028 on NVD →
FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter
critical
The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authentication middleware...
- CVSS:
- 9.1
- Affected:
- up to 1.9.2
- Fixed in:
- 1.10.0
- Disclosed:
- Jul 31, 2026
CVE-2026-3141 on NVD →
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.4.2 - Unauthenticated Arbitrary File Deletion
critical
The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to delete...
- CVSS:
- 9.1
- Affected:
- up to 1.4.2
- Fix:
- No patched version reported
- Disclosed:
- Mar 3, 2026
CVE-2026-22460 on NVD →
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More [formgent] < 1.0.4
unknown
[en] The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.
- Affected:
- up to 1.0.4
- Fixed in:
- 1.0.4
- Disclosed:
- Oct 21, 2025
CVE-2025-10916 on NVD →
FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More < 1.0.4 - Unauthenticated Arbitrary File Deletion
high
The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp-json/formgent/responses/attachments REST endpoint in all versions up to, and including, 1.0.3. This makes it po...
- CVSS:
- 7.5
- Affected:
- up to 1.0.3
- Fixed in:
- 1.0.4
- Disclosed:
- Sep 30, 2025
CVE-2025-10916 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database