A security flaw has been found in the FormGent plugin for WordPress, affecting all versions up to and including 1.9.2. The issue is caused by a file management feature in the plugin that does not require any user authentication or permission checks to access. This lets unauthenticated attackers delete files stored in the FormGent plugin's upload folder on your website.
On standard Linux-based WordPress hosting servers, if the plugin's default upload folder has not yet been created after you installed FormGent, this flaw is significantly more severe. Attackers can bypass the plugin's built-in path protection to delete any file on your site, including the core wp-config.php file that runs your WordPress installation. Deleting this file can allow an attacker to take full control of your site by performing a fresh WordPress installation.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-3141