Description
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting — combined with the `super_submit_form` handler's `submit_form` function passing the attacker-controlled `files[].subdir` value from `$_POST['data']` directly into `SUPER_Common::delete_dir()` without sanitization, and a trivially bypassed `ABSPATH` guard that a `subdir` value of `wp-config.php` defeats because `dirname(realpath(ABSPATH . $subdir))` resolves to the WordPress root while the naive `ABSPATH !== $dir` string check fails to match due to a trailing-slash mismatch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recursively delete arbitrary files and directories on the server, up to and including the entire WordPress installation, resulting in full site takedown and potential remote code execution if critical files such as `wp-config.php` are removed and the site is subsequently re-installed by another party.
Published: 2026-10-01
Score: 8.1 High
EPSS: n/a
KEV: No
Impact: Arbitrary File and Directory Deletion leading to full site takeover and possible remote code execution
Action: Immediate Patch
AI Analysis

Impact

The flaw allows an authenticated user with Subscriber level or higher to invoke an AJAX handler that performs file and directory deletions with the attacker-controlled subdir value passed directly into the delete function, bypassing sanitization and path checks. By choosing a subdir such as wp-config.php, the attacker can remove critical configuration files, causing the WordPress installation to fail and potentially enabling malicious code injection during a reinstall.

Affected Systems

WordPress plugin Super Forms – Drag & Drop Form Builder, vendor WebRehab, affected in all releases up to and including version 6.3.316.

Risk and Exploitability

The CVSS score of 8.1 indicates a high severity flaw, and while the EPSS score is not registered, the vulnerability can be exercised by any authenticated user who can access the form builder interface, making the risk of complete site compromise real. No mention in CISA KEV suggests it is not yet widely exploited, but the impact of full site takedown and potential for subsequent remote code execution makes it a high priority.

Generated by OpenCVE AI on October 1, 2026 at 11:08 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Super Forms to the latest version that includes the deletion check fix.
  • If an upgrade is not immediately possible, disable the file_upload_submission_delete setting in the plugin options to prevent unintended deletions.
  • Review user role assignments and restrict Subscriber and lower roles from accessing the form builder or grant form creation permissions only to trusted administrators.

Generated by OpenCVE AI on October 1, 2026 at 11:08 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Webrehab
Webrehab super Forms – Drag & Drop Form Builder
Wordpress-extensions
Wordpress-extensions super Forms
Vendors & Products Webrehab
Webrehab super Forms – Drag & Drop Form Builder
Wordpress-extensions
Wordpress-extensions super Forms

Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting — combined with the `super_submit_form` handler's `submit_form` function passing the attacker-controlled `files[].subdir` value from `$_POST['data']` directly into `SUPER_Common::delete_dir()` without sanitization, and a trivially bypassed `ABSPATH` guard that a `subdir` value of `wp-config.php` defeats because `dirname(realpath(ABSPATH . $subdir))` resolves to the WordPress root while the naive `ABSPATH !== $dir` string check fails to match due to a trailing-slash mismatch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recursively delete arbitrary files and directories on the server, up to and including the entire WordPress installation, resulting in full site takedown and potential remote code execution if critical files such as `wp-config.php` are removed and the site is subsequently re-installed by another party.
Title Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' Parameter
Weaknesses CWE-73
References
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Webrehab Super Forms – Drag & Drop Form Builder
Wordpress-extensions Super Forms
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T08:28:41.509Z

Reserved: 2026-07-16T17:09:44.014Z

Link: CVE-2026-15983

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T09:17:09.223

Modified: 2026-10-01T12:40:28.083

Link: CVE-2026-15983

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:36:20Z

Weaknesses
  • CWE-73

    External Control of File Name or Path