Arbitrary Directory Deletion Vulnerability in Super Forms Plugin for WordPress
CVE-2026-17609
9.1CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 October 2026
What is CVE-2026-17609?
The Super Forms β Drag & Drop Form Builder plugin for WordPress has a vulnerability allowing unauthenticated attackers to delete arbitrary directories on the server. This arises from inadequate validation of user-controlled JSON field declarations against the form schema and a bypass of the ABSPATH guard. This exploitation is contingent upon an administrator enabling the 'Delete files from server after form submissions' feature, a common configuration that increases the risk of potential data loss and should be addressed immediately.
Affected Version(s)
Super Forms β Drag & Drop Form Builder 0 <= 6.3.316