All 2 CVE vulnerabilities found in FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More, with AI-generated Chinese analysis, references, and POCs.
Vendor: wpwax
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2025-15028 | FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More <= 1.9.2 - Unauthenticated Stored Cross-Site Scripting CWE-79 | 7.2 | High | 2026-08-06 |
| CVE-2026-3141 | FormGent <= 1.9.2- Missing Authorization to Unauthenticated Arbitrary File Deletion via 'file_token' Parameter CWE-862 | 9.1 | Critical | 2026-08-01 |
All 2 known CVE vulnerabilities affecting FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More with full Chinese analysis, references, and POCs where available.