critical
CVE-2026-3141
FormGent unauthenticated arbitrary file deletion via REST API (wp-config.php -> site takeover)
- Severity
- critical
- Affected product
- formgent
- Affected versions
- formgent ≤ 1.0.9
- Fixed in
- formgent a release above 1.0.9
- Added to NewScan
- 2026-08-01
- Detected by
- NewScan — free, self-hosted
How NewScan reports it
COMPONENT VERSION RANGE
NewScan fingerprints formgent from its response and reports this CVE when the detected version falls inside the affected range below.
References
Scan for this yourself — local, in-band scanning is free.
Get NewScan (FREE) →