{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/formgent--1.9.2/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-3141"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FormGent (\u003c= 1.9.2)"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe FormGent WordPress plugin (versions 1.9.2 and earlier) contains a critical security vulnerability (CVE-2026-3141) stemming from a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint. The registration of this endpoint in routes/rest/api.php lacks necessary authentication middleware, allowing unauthenticated remote attackers to trigger file deletion processes. The vulnerability is compounded by insufficient path traversal validation, particularly in default installations where the expected target directory does not yet exist. Attackers can exploit this to delete sensitive files, including the WordPress configuration file wp-config.php. Once wp-config.php is removed, the target site effectively reverts to an uninitialized state, permitting an attacker to perform a fresh WordPress installation and gain complete administrative control over the application and underlying data.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for the permanent deletion of arbitrary files on the web server, leading to potential denial of service or full site takeover. Organizations running vulnerable versions of FormGent are at risk of data loss and administrative compromise. While the specific number of affected installations is not provided, the plugin's presence across the WordPress ecosystem presents a significant risk to affected web servers.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the FormGent plugin to the latest patched version to remediate CVE-2026-3141.\u003c/li\u003e\n\u003cli\u003eReview web server access logs for anomalous POST requests targeting the /wp-json/formgent/responses/attachments endpoint.\u003c/li\u003e\n\u003cli\u003eAudit file system integrity for the presence of the wp-config.php file in the WordPress root directory to ensure it has not been removed.\u003c/li\u003e\n\u003cli\u003eImplement strict file system permissions for the web server user, preventing the deletion of critical WordPress configuration files.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-01T07:49:18Z","date_published":"2026-08-01T07:49:18Z","id":"https://feed.craftedsignal.io/briefs/2026-08-formgent-vulnerability/","summary":"The FormGent WordPress plugin is vulnerable to unauthorized arbitrary file deletion via an unauthenticated REST API endpoint, potentially allowing attackers to delete critical files like wp-config.php and achieve site takeover.","title":"Unauthenticated Arbitrary File Deletion in FormGent WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-formgent-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - FormGent (\u003c= 1.9.2)","version":"https://jsonfeed.org/version/1.1"}