CVE-2025-10916
critical · 9.1The FormGent WordPress plugin before 1.0.4 is vulnerable to arbitrary file deletion due to insufficient file path validation. This makes it possible for unauthenticated attackers to delete arbitrary files on the server.
9.1
CVSS
0.3%
EPSS (exploit prob.)
25th
EPSS percentile
2025-10-21
Published
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
References
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2025-10916