
CVE-2026-3141: FormGent WordPress Plugin Unauthorized File Deletion - What It Means for Your Business and How to Respond https://hubs.li/Q04xMY380
Signal is active with 1 mentions in latest observed window
Recommended action window: Monitor and triage in normal cycle
Priority
LOW
Exploitation
NONE
PoC
NONE
Patch
AVAILABLE
Momentum
STABLE

CVE-2026-3141: FormGent WordPress Plugin Unauthorized File Deletion - What It Means for Your Business and How to Respond https://hubs.li/Q04xMY380

Critical flaw in the FormGent WordPress plugin (CVE-2026-3141, CVSS 9.1): unauthenticated attackers can delete arbitrary files incl. wp-config.php, leading to full site takeover. Versions ≤1.9.2 affected. Update now. A single unauthorised request from the internet can be enough to take over a WordPress website completely – with no login, no password, and without any staff member having to click on anything. That is precisely what a critical vulnerability in the WordPress plugin FormGent, an AI-powered form builder, makes possible. The flaw, identified as CVE-2026-3141, carries a CVSS score of 9.1 out of 10 and allows attackers to delete arbitrary files on the server – in the worst case the central configuration file wp-config.php. If this is removed, WordPress believes it has been freshly installed, and an attacker can link the site to their own database and make themselves an administrator. If you are running FormGent in a version up to and including 1.9.2, you should act now. A security update is already available. We explain exactly what happened, how to check whether your site is affected, and what specific steps you need to take. #WordPress #CyberSecurity https://shieldgaps.com/en/news/formgent-plugin-critical-flaw-allows-site-takeover-cve-2026-3141-173
Post summary
The post announces a critical flaw in the FormGent WordPress plugin, explains its impact and technical details, and urges users to apply the available security update.