CVE-2025-10916
CRITICAL 9.1EPSS 0.3%
The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.
- CVSS v3.1
- 9.1 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H - EPSS
- 0.32% chance of exploitation in the next 30 days, 24th percentile
- Published
- 2025-10-21