The FormGent – Next-Gen AI Form Builder for WordPress with Multi-Step, Quizzes, Payments & More plugin for WordPress is vulnerable to Stored Cross-Site Scripting via form submission fields in all versions up to, and including, 1.9.2 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whe [truncated]
The FormGent plugin for WordPress has a critical vulnerability, CVE-2026-3141, with a CVSS score of 9.1. The vulnerability allows unauthenticated attackers to delete arbitrary files within the formgent uploads directory due to a missing capability check on the /wp-json/formgent/responses/attachments REST API endpoint. On Linux servers where the wp-content/uploads/formgent directory does not exist, the pat [truncated]
The CVE record for CVE-2026-59518 was published on 2026-07-13T10:16:45.977Z and has not been modified since then. The NVD entry is currently 9.8 CRITICAL. A Deserialization of Untrusted Data vulnerability in wpWax Directorist directorist allows Object Injection. This issue affects Directorist: from n/a through <= 8.8.2. The vulnerability has a CVSS score of 9.8 and a severity of CRITICAL. Users of wpWax D [truncated]
A SQL injection vulnerability was discovered in Directorist Booking, a WordPress plugin developed by wpWax. The issue, tracked as CVE-2026-49073, allows for Blind SQL Injection and has a CVSS score of 8. This vulnerability is caused by improper neutralization of special elements used in an SQL command. Users of the Directorist Booking plugin, particularly those with versions prior to 3.0.4, should be awar [truncated]
A Missing Authorization vulnerability in wpWax Directorist directorist allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Directorist: from n/a through <= 8.5.10. The vulnerability has a CVSS score of 5.3 and is classified as MEDIUM severity. Users of Directorist plugin for WordPress, version 8.5.10 or earlier, should apply patches or mitigations to prevent potenti [truncated]