CVE-2026-15983
Received Received - Intake

Arbitrary File Deletion in Super Forms WordPress Plugin

Vulnerability report for CVE-2026-15983, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Wordfence

Description

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check β€” allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting β€” combined with the `super_submit_form` handler's `submit_form` function passing the attacker-controlled `files[].subdir` value from `$_POST['data']` directly into `SUPER_Common::delete_dir()` without sanitization, and a trivially bypassed `ABSPATH` guard that a `subdir` value of `wp-config.php` defeats because `dirname(realpath(ABSPATH . $subdir))` resolves to the WordPress root while the naive `ABSPATH !== $dir` string check fails to match due to a trailing-slash mismatch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recursively delete arbitrary files and directories on the server, up to and including the entire WordPress installation, resulting in full site takedown and potential remote code execution if critical files such as `wp-config.php` are removed and the site is subsequently re-installed by another party.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
super_forms drag_and_drop_form_builder to 6.3.316 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Super Forms WordPress plugin allows authenticated users with Subscriber-level access or higher to delete arbitrary files and directories on the server. It occurs due to missing capability checks and improper sanitization of user-controlled input in the file deletion process. Attackers can exploit this to recursively delete files, including critical WordPress files like wp-config.php, potentially leading to full site takedown or remote code execution if the site is reinstalled.

Detection Guidance

Check for unauthorized file deletions in WordPress directories, especially in the wp-content/uploads/super-forms directory. Review server logs for POST requests to /wp-admin/admin-ajax.php with super_save_form or super_submit_form actions. Inspect WordPress user roles for unexpected Subscriber-level access.

Impact Analysis

If you use the Super Forms plugin on your WordPress site, an attacker with basic user access could delete important files, including your entire WordPress installation. This would cause your website to stop functioning, potentially losing all data and requiring a full reinstall. If critical files like wp-config.php are deleted, an attacker could later take over the site when it is reinstalled by another party.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by enabling unauthorized data destruction or loss of sensitive information. GDPR requires protecting personal data, and HIPAA mandates safeguarding protected health information. A successful attack could result in data breaches, unauthorized access, or permanent loss of critical records, triggering regulatory penalties and legal consequences.

Mitigation Strategies

Update the Super Forms plugin to the latest version immediately. Remove Subscriber-level access for untrusted users. Disable file upload submissions if not required. Monitor for unusual file deletions and restrict wp-content/uploads directory permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15983. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart