---
id: CVE-2025-10916
title: >-
  The FormGent  WordPress plugin before 1.0.4 is vulnerable to arbitrary file
  deletion due to insufficient file path validation
summary: >-
  The FormGent  WordPress plugin before 1.0.4 is vulnerable to arbitrary file
  deletion due to insufficient file path validation. This makes it possible for
  unauthenticated attackers to delete arbitrary files on the server.
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
published: '2025-10-21'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:10:00.563'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-10916'
references:
  - url: 'https://wpscan.com/vulnerability/81c23998-1abb-495f-890a-79624a4cab9a/'
    label: contact@wpscan.com
  - url: 'https://wpscan.com/vulnerability/81c23998-1abb-495f-890a-79624a4cab9a/'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
epss: 0.00339
epssPercentile: 0.25281
ingestedAt: '2026-10-08T22:11:53.828Z'
---

## Overview

The FormGent  WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
