Impact
The Super Forms – Drag & Drop Form Builder plugin for WordPress allows an unauthenticated attacker to delete arbitrary directories on the server. The flaw resides in the submit_form function, which fails to properly validate attacker‑controlled JSON field declarations and contains a non‑effective ABSPATH guard. An attacker can exploit this by submitting a form that includes a 'data[...][files][][subdir]' parameter pointing to any path, causing the plugin to call dirname() and bypass the path restriction. Deleting directories such as the WordPress root can render the site inoperable and permanently compromise data integrity.
Affected Systems
All installed instances of the WebRehab: Super Forms – Drag & Drop Form Builder plugin with version 6.3.316 or earlier are affected. This includes every WordPress site using the plugin prior to upgrade beyond 6.3.316. No other vendors or products are explicitly listed.
Risk and Exploitability
The CVSS score of 9.1 reflects high severity, and although the EPSS score is not published, the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a crafted HTTP request to the form endpoint; no authentication is required. Exploitation requires that the administrative setting 'Delete files from server after form submissions' is enabled, a feature that is documented and commonly enabled, which increases the potential for widespread impact.
OpenCVE Enrichment