What is CVE-2026-3141?
The FormGent plugin for WordPress (up to v1.9.2) contains an unauthenticated arbitrary file deletion vulnerability due to a missing capability check on the '/wp-json/formgent/responses/attachments' REST API endpoint. This allows attackers without permission to delete critical files on the server. Updating the plugin immediately is recommended.
Azərbaycanca: WordPress-in FormGent plaginində (v1.9.2-dək) autentifikasiya olunmamış ixtiyari fayl silmə zəifliyi aşkarlanıb. Bu boşluq '/wp-json/formgent/responses/attachments' REST API endpoint-də səlahiyyət yoxlamasının olmaması səbəbindən yaranır. Təcili olaraq plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the FormGent plugin are affected by CVE-2026-3141?
The vulnerability affects all versions of the FormGent plugin up to v1.9.2.
Where does the CVE-2026-3141 vulnerability reside?
The vulnerability lies in a missing capability check on the '/wp-json/formgent/responses/attachments' REST API endpoint.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.