Arbitrary Directory Deletion Vulnerability in Super Forms Plugin for WordPress
CVE-2026-17609

9.1CRITICAL

What is CVE-2026-17609?

The Super Forms – Drag & Drop Form Builder plugin for WordPress has a vulnerability allowing unauthenticated attackers to delete arbitrary directories on the server. This arises from inadequate validation of user-controlled JSON field declarations against the form schema and a bypass of the ABSPATH guard. This exploitation is contingent upon an administrator enabling the 'Delete files from server after form submissions' feature, a common configuration that increases the risk of potential data loss and should be addressed immediately.

Affected Version(s)

Super Forms – Drag & Drop Form Builder 0 <= 6.3.316

References

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

d.v4n_s3c
.