FormGent WordPress Plugin Arbitrary File Deletion Vulnerability

Vulnerability

A vulnerability allowing unauthenticated arbitrary file deletion has been identified in the FormGent WordPress plugin, affecting versions prior to 1.0.4. The issue arises from inadequate validation of file paths, enabling attackers to delete arbitrary files on the server.

Impact

Exploitation of this vulnerability allows for unauthorized deletion of files on the server, which could lead to loss of critical data or disruption of website functionality.

Reproduction

To reproduce this vulnerability, send a DELETE request to the WordPress REST API endpoint for the FormGent plugin, specifically targeting the 'responses/attachments' resource. Include a 'file_token' in the request payload that references a file to be deleted, such as the 'wp-config.php' file, relative to the 'wp-content/uploads/' directory. A successful exploitation will return an HTTP 204 No Content response.

Remediation

Users are advised to update the FormGent WordPress plugin to version 1.0.4 or later.

Added: Oct 21, 2025, 6:17 AM
Updated: Oct 21, 2025, 6:17 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
0.0
exploitability
8.7
remediation
7.7
relevance
0.7
threat
6.4
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.