External risk intelligence

FormGent WordPress Plugin Arbitrary File Deletion Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2025-10916

The vulnerability affects a WordPress plugin, which is a component of a web application. WordPress sites are frequently deployed as public-facing web services, making the plugin's functionality and its associated attack surface commonly reachable via the internet.

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the FormGent WordPress plugin allows unauthenticated attackers to delete any file on the server. This issue, due to insufficient validation of file paths, could potentially impact the integrity and availability of web services.

  • Plugin allows deleting any file.
  • Threatens website integrity and availability.
  • Confirm if this plugin is in use.

Attack Path

How an attacker could exploit the issue

An unauthenticated attacker can exploit this vulnerability by interacting with the FormGent WordPress plugin. The flaw in how the plugin handles file paths allows an attacker to delete any file on the server. This could lead to a complete system compromise or denial of service.

  • Attacker needs no login to access.
  • Attacker triggers by using a crafted request.
  • Risk is arbitrary file deletion.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could delete arbitrary files on a server when the FormGent WordPress plugin is used. This could affect system data and service availability depending on the files targeted.

  • System files and service configuration.
  • Arbitrary file deletion via crafted requests.
  • Unavailability and potential system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the FormGent WordPress plugin likely requires action from teams managing web applications and their components. The immediate first step is to identify all instances of the FormGent plugin within your WordPress deployments, assess their exposure to the internet, and determine their criticality to business operations. Once identified and prioritized, you can assign the issue to the accountable owner for remediation planning.

  • Web application and platform teams.
  • Verify plugin presence and network exposure.
  • Plan and execute remediation actions.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the FormGent WordPress plugin?

FormGent is a WordPress plugin designed to help site administrators manage and process web forms. Like many plugins in the WordPress ecosystem, it extends the core platform's functionality to capture user input, manage submissions, and store data directly on the web server.

What does CVE-2025-10916 mean in plain English?

This vulnerability is an improper input validation flaw. Essentially, the plugin does not properly check the file paths provided to it. This oversight allows an unauthorized party to specify which files the server should delete, potentially removing critical system or configuration files.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending a specifically crafted network request to the plugin. They do not need to be logged into the website to succeed. Note that simply visiting the site or interacting with standard forms does not trigger the issue; the attacker must intentionally send a malicious request designed to manipulate the file path.

Is my website at risk if I use FormGent?

According to Halo Surface Signal, this risk is relevant because FormGent is a web-based component. WordPress sites are typically deployed as public-facing services, meaning the plugin's attack surface is often reachable via the internet. If your site is accessible online, the plugin could be reachable by remote attackers.

What steps should I take to respond to this issue?

First, conduct an inventory of your WordPress environments to confirm if the FormGent plugin is installed. If found, evaluate how critical that site is to your operations. Once you have identified the affected systems, prepare to update the plugin or remove it entirely to eliminate the possibility of unauthorized file deletion.

References