plugin

Formgent Vulnerabilities

5 known security issues reported for the Formgent WordPress plugin. Most recent disclosed Aug 5, 2026.

2 critical 2 high

Running Formgent on your site? Check whether your installed version is affected.

Scan your site free

FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting

high

The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission fields in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for...

CVSS:
7.2
Affected:
up to 1.9.2
Fixed in:
1.10.0
Disclosed:
Aug 5, 2026

CVE-2025-15028 on NVD →

FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter

critical

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authentication middleware...

CVSS:
9.1
Affected:
up to 1.9.2
Fixed in:
1.10.0
Disclosed:
Jul 31, 2026

CVE-2026-3141 on NVD →

FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.4.2 - Unauthenticated Arbitrary File Deletion

critical

The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in a function in all versions up to, and including, 1.4.2. This makes it possible for unauthenticated attackers to delete...

CVSS:
9.1
Affected:
up to 1.4.2
Fix:
No patched version reported
Disclosed:
Mar 3, 2026

CVE-2026-22460 on NVD →

FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments &amp; More [formgent] < 1.0.4

unknown

[en] The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

Affected:
up to 1.0.4
Fixed in:
1.0.4
Disclosed:
Oct 21, 2025

CVE-2025-10916 on NVD →

FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More < 1.0.4 - Unauthenticated Arbitrary File Deletion

high

The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation in the wp-json/formgent/responses/attachments REST endpoint in all versions up to, and including, 1.0.3. This makes it po...

CVSS:
7.5
Affected:
up to 1.0.3
Fixed in:
1.0.4
Disclosed:
Sep 30, 2025

CVE-2025-10916 on NVD →

Protect your WordPress site

Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.

Scan your site free

← Back to the vulnerability database