CRITICAL 9.1 CVE-2026-17609 Published 8 Oct 2026

Super Forms WordPress Plugin Arbitrary Directory Deletion Vulnerability

Worried this affects your website?

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316.

The flaw exists in the submit_form function due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema. A non-effective ABSPATH guard can be bypassed by dirname() stripping the trailing slash.

  • Unauthenticated attackers can recursively delete arbitrary directories on the server, including the WordPress root directory.
  • Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, a documented and commonly-enabled feature.

Reference: CVE-2026-17609 on NVD

← Back to Security News