CVE-2026-3141 (matched: wordpress)

  • Monday, 3rd August, 2026
  • 10:04am

A security vulnerability has been identified in the FormGent plugin for WordPress, a tool many site owners use to manage form submissions and user-uploaded files. The flaw impacts all versions of the plugin up to and including version 1.9.2.

The vulnerability exists because the plugin's built-in file-management tool does not require users to log in or prove they have permission to access it. This allows unauthenticated third parties to delete files stored in the plugin's designated uploads folder on your site.

On most WordPress sites running on Linux servers, this flaw can be further exploited to bypass path protections, as the plugin's uploads folder does not exist by default immediately after installation. This makes it possible for attackers to delete arbitrary files on your site, including the core WordPress configuration file that controls your entire site. If that critical file is deleted, an attacker could take full control of your site by installing a fresh copy of WordPress on your domain.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-3141

« Back