Impact
The Formidable Digital Signatures plugin for WordPress is vulnerable to a file deletion flaw caused by inadequate file path validation in the delete_file function. An attacker who is not logged in can supply a crafted filename through the item_meta[field_id][content] parameter along with the delete_saved_image flag during a standard form submission, causing the server to delete the targeted file. The weakness is identified as CWE‑23, a path traversal vulnerability, and can lead to the loss of essential site files and compromise of site availability and integrity.
Affected Systems
All WordPress installations that use the Formidable Digital Signatures plugin from Strategy11 with a version of 3.0.6 or earlier are affected. The vulnerability is present in every release up to and including 3.0.6.
Risk and Exploitability
The CVSS score of 9.8 signals a critical severity, but the EPSS score of less than 1% indicates that exploitation is currently unlikely to be widespread. The flaw can be exploited via the public anonymous submission endpoint, meaning no authentication is required. Although no KEV listing exists, the combination of high impact and a readily available exploit vector warrants urgent attention.
OpenCVE Enrichment