A security vulnerability has been found in the FormGent plugin for WordPress, affecting all versions up to and including 1.9.2. The flaw means the plugin's file deletion feature does not require valid login credentials to use, so people who do not have authorized access to your WordPress site can delete files stored in the plugin's dedicated uploads folder.
On Linux hosting servers, if the plugin's default upload directory has not yet been created (the standard state immediately after installing the plugin), attackers can bypass the plugin's built-in path restrictions to delete arbitrary files anywhere on your site. This includes critical core files like wp-config.php; if this file is deleted, bad actors can take full, unauthorized control of your website by running a fresh WordPress installation.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-3141