Description
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server, including the WordPress root directory. Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, though this is a documented and commonly-enabled feature.
Published: 2026-10-08
Score: 9.1 Critical
EPSS: n/a
KEV: No
Impact: Arbitrary Directory Deletion
Action: Patch Immediately
AI Analysis

Impact

The Super Forms – Drag & Drop Form Builder plugin for WordPress allows an unauthenticated attacker to delete arbitrary directories on the server. The flaw resides in the submit_form function, which fails to properly validate attacker‑controlled JSON field declarations and contains a non‑effective ABSPATH guard. An attacker can exploit this by submitting a form that includes a 'data[...][files][][subdir]' parameter pointing to any path, causing the plugin to call dirname() and bypass the path restriction. Deleting directories such as the WordPress root can render the site inoperable and permanently compromise data integrity.

Affected Systems

All installed instances of the WebRehab: Super Forms – Drag & Drop Form Builder plugin with version 6.3.316 or earlier are affected. This includes every WordPress site using the plugin prior to upgrade beyond 6.3.316. No other vendors or products are explicitly listed.

Risk and Exploitability

The CVSS score of 9.1 reflects high severity, and although the EPSS score is not published, the vulnerability is not currently listed in the CISA KEV catalog. The likely attack vector is a crafted HTTP request to the form endpoint; no authentication is required. Exploitation requires that the administrative setting 'Delete files from server after form submissions' is enabled, a feature that is documented and commonly enabled, which increases the potential for widespread impact.

Generated by OpenCVE AI on October 8, 2026 at 06:52 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Super Forms to a version newer than 6.3.316, which removes the insecure delete logic.
  • If an update cannot be applied immediately, disable the 'Delete files from server after form submissions' option in the plugin settings to prevent directory removals.
  • After disabling the feature, monitor form submission logs for anomalous subdir values and audit filesystem integrity to detect any prior loss.

Generated by OpenCVE AI on October 8, 2026 at 06:52 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:00:00 +0000

Type Values Removed Values Added
Description The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server, including the WordPress root directory. Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, though this is a documented and commonly-enabled feature.
Title Super Forms <= 6.3.316 - Unauthenticated Arbitrary Directory Deletion via 'data[...][files][][subdir]' Parameter
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-08T04:28:51.521Z

Reserved: 2026-07-27T17:19:33.878Z

Link: CVE-2026-17609

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T05:17:04.793

Modified: 2026-10-08T05:17:04.793

Link: CVE-2026-17609

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T07:00:10Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type