CVE-2026-17609
Received Received - Intake

Arbitrary Directory Deletion in Super Forms WordPress Plugin

Vulnerability report for CVE-2026-17609, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: Wordfence

Description

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server, including the WordPress root directory. Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, though this is a documented and commonly-enabled feature.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-08
AI Q&A
2026-10-08
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
WebRehab Super Forms – Drag & Drop Form Builder 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-434 The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability in the Super Forms WordPress plugin allows unauthenticated attackers to delete arbitrary directories on the server, including the WordPress root directory. It occurs due to insufficient validation of attacker-controlled JSON input in the submit_form function, combined with a weak path sanitization check that can be bypassed.

Detection Guidance

Check WordPress sites using Super Forms plugin versions up to 6.3.316. Look for unauthorized directory deletions or suspicious form submissions. Review server logs for dirname() bypass attempts or JSON field manipulation in form data.

Impact Analysis

If exploited, this vulnerability could allow attackers to delete critical files and directories on your server, potentially crashing your website or causing data loss. It requires the 'Delete files from server after form submissions' setting to be enabled, which is commonly used.

Compliance Impact

This vulnerability could lead to unauthorized data deletion or system compromise, violating GDPR's integrity principle or HIPAA's availability requirements. Organizations may face compliance violations if exploited.

Mitigation Strategies

Immediately update the Super Forms plugin to the latest version. Disable the 'Delete files from server after form submissions' setting. Implement file system monitoring to detect unauthorized deletions. Consider temporary removal of the plugin if an update is unavailable.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-17609. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart