[CYBERDIGEST]
⊞ Dashboard ⚡ Intelligence 📝 Reports 📚 Global Threats 💻 Hack Lab 🗄️ Resources ⌬ 0xJerry's Lab
📡 RSS Feed
System Online

Tag

#FormGent

articleCRITICAL 9.1

Critical Vulnerability in FormGent WordPress Plugin Allows Unauthenticated Arbitrary File Deletion

The FormGent plugin for WordPress is vulnerable to unauthorized arbitrary file deletion due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint in all versions up to, and including, 1.9.2. This critical vulnerability, with a CVSS score of 9.1, allows unauthenticated attackers to delete arbitrary files within the formgent uploads directory and potentially bypass path traversal protection to delete critical files like wp-config.php, leading to complete site takeover. Immediate patching is recommended.

Aug 2, 20261 source