CRITICAL
9.1 CVE-2026-17609 Published 8 Oct 2026
Super Forms WordPress Plugin Arbitrary Directory Deletion Vulnerability
Worried this affects your website?
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316.
The flaw exists in the submit_form function due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema. A non-effective ABSPATH guard can be bypassed by dirname() stripping the trailing slash.
- Unauthenticated attackers can recursively delete arbitrary directories on the server, including the WordPress root directory.
- Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, a documented and commonly-enabled feature.
Reference: CVE-2026-17609 on NVD
← Back to Security News