Critical
Low
Medium

CVE-2025-10916

Alias:

Overview

The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

Critical
Low
Medium
No items found.

Severity / CVSS Score:  (Critical)

CWE:

Discovery date: October 21, 2025

Authentication required: NoneYes

Attack Vector: None

Affected Components

Kodem Deep Dive

Stop the waste.
Protect your environment with Kodem.

Get a personalized demo
Get a personalized demo