---
id: CVE-2026-3141
title: >-
  The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file
  deletion due to a missing capability check on the
  /wp-json/formgent/responses/attachments REST API endpoint in all versions up
  to, and including, 1.9.2 This i…
summary: >-
  The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file
  deletion due to a missing capability check on the
  /wp-json/formgent/responses/attachments REST API endpoint in all versions up
  to, and including, 1.9.2 This i…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-862
published: '2026-08-01'
updated: '2026-08-01'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-3141'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/formgent/tags/1.3.1/app/Http/Controllers/AttachmentController.php#L59
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/formgent/tags/1.3.1/routes/rest/api.php#L27
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/formgent/trunk/app/Http/Controllers/AttachmentController.php#L59
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/formgent/trunk/routes/rest/api.php#L27
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset/3604540/formgent/trunk/app/Http/Controllers/AttachmentController.php
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?old_path=%2Fformgent/tags/1.9.2&new_path=%2Fformgent/tags/1.10.0
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/097a9d0f-fa38-4fdc-9048-43dd65e7652c?source=cve
    label: security@wordfence.com
tags:
  - nvd
epss: 0.00565
epssPercentile: 0.4573
ingestedAt: '2026-08-02T01:16:31.996Z'
---

## Overview

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2 This is due to the REST API route being registered without any authentication middleware in routes/rest/api.php. This makes it possible for unauthenticated attackers to delete arbitrary files within the formgent uploads directory. Additionally, on Linux servers where the wp-content/uploads/formgent directory does not yet exist (the default state after plugin installation), the path traversal protection can be bypassed, enabling deletion of arbitrary files including wp-config.php which can lead to complete site takeover via a fresh WordPress installation.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
