PoC Index

CVE-2025-10916

CRITICAL 9.1EPSS 0.3%

The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.

CVSS v3.1
9.1 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS
0.32% chance of exploitation in the next 30 days, 24th percentile
Published
2025-10-21

Proof-of-concept exploits (1)

References

Related