WORDPRESS · AUGUST 2026 · EARLY WARNING

FormGent WordPress Plugin Vulnerability: Unauthorized File Deletion Risk

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
CVE-2026-3141Severity: CRITICAL

The FormGent plugin for WordPress is reportedly vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the REST API endpoint, potentially leading to complete site takeover.

What happened

The FormGent plugin for WordPress, in versions up to and including 1.9.2, appears to be vulnerable to unauthorized arbitrary file deletion. This is due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint, which is registered without any authentication middleware. This vulnerability allows unauthenticated attackers to delete files within the formgent uploads directory. On Linux servers where the wp-content/uploads/formgent directory does not yet exist, the path traversal protection can be bypassed, enabling deletion of arbitrary files including wp-config.php, which can lead to complete site takeover.

Professional software engineers using the FormGent plugin should assess their exposure by checking if they are running a version up to and including 1.9.2. It is under investigation whether a fix is available. As a recommended action, engineers should upgrade the FormGent plugin to a version with the fix if available, or remove the plugin if no fix is available. For more detailed information, primary sources should be consulted.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If formgent is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats