CVE-2026-3141 (matched: wordpress)

  • Saturday, 1st August, 2026
  • 16:04pm

A security vulnerability has been discovered in the FormGent plugin for WordPress, affecting all versions up to and including 1.9.2. The flaw occurs because the plugin’s REST API endpoint for managing uploaded form response files does not require user authentication, meaning unauthenticated attackers (people without login access to your WordPress site) can delete files stored in the plugin’s designated uploads folder.

On Linux servers, if the plugin’s default uploads directory has not yet been created after installation, attackers can bypass the plugin’s path traversal protections. This allows them to delete arbitrary files across your site, including the critical wp-config.php file that holds your site’s core configuration credentials. If this file is deleted, an attacker could take full control of your website by completing a fresh WordPress installation.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-3141

« Back