Impact
The flaw allows an authenticated user with Subscriber level or higher to invoke an AJAX handler that performs file and directory deletions with the attacker-controlled subdir value passed directly into the delete function, bypassing sanitization and path checks. By choosing a subdir such as wp-config.php, the attacker can remove critical configuration files, causing the WordPress installation to fail and potentially enabling malicious code injection during a reinstall.
Affected Systems
WordPress plugin Super Forms – Drag & Drop Form Builder, vendor WebRehab, affected in all releases up to and including version 6.3.316.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity flaw, and while the EPSS score is not registered, the vulnerability can be exercised by any authenticated user who can access the form builder interface, making the risk of complete site compromise real. No mention in CISA KEV suggests it is not yet widely exploited, but the impact of full site takedown and potential for subsequent remote code execution makes it a high priority.
OpenCVE Enrichment