CVE-2026-15983: Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' Parameter
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the supersaveform AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super Forms and enable the fileuploadsubmissiondelete setting — combined with the supersubmitform handler's submitform function passing the attacker-controlled files[].subdir value from $POST['data'] directly into SUPERCommon::deletedir() without sanitization, and a trivially bypassed ABSPATH guard that a subdir value of wp-config.php defeats because dirname(realpath(ABSPATH . $subdir)) resolves to the WordPress root while the naive ABSPATH !== $dir string check fails to match due to a trailing-slash mismatch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recursively delete arbitrary files and directories on the server, up to and including the entire WordPress installation, resulting in full site takedown and potential remote code execution if critical files such as wp-config.php are removed and the site is subsequently re-installed by another party.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs an authenticated WordPress account with at least Subscriber-level access. No additional capability check is performed by the affected form-saving AJAX handler.
What access or configuration is required for exploitation?
The attacker must be able to create or modify a Super Forms form and enable the file_upload_submission_delete setting. They can then submit attacker-controlled files[].subdir data to trigger deletion.
What is the likely impact of successful exploitation?
An attacker can recursively delete arbitrary files and directories on the server, including the WordPress installation. This can cause a complete site outage and may lead to remote code execution if critical files such as wp-config.php are deleted.
How can organizations reduce risk before updating?
Restrict or remove Subscriber and other low-privilege authenticated accounts that are not required, since Subscriber-level access is sufficient. Also prevent untrusted users from creating or modifying Super Forms and enabling its submission-file deletion setting.