CVE-2026-17609: Super Forms <= 6.3.316 - Unauthenticated Arbitrary Directory Deletion via 'data[...][files][][subdir]' Parameter
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submitform function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server, including the WordPress root directory. Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, though this is a documented and commonly-enabled feature.
Affected Software
Event History
Frequently Asked Questions
Which deployments are exposed to unauthenticated exploitation?
WordPress sites using Super Forms versions up to and including 6.3.316 are exposed if an administrator has enabled the “Delete files from server after form submissions” setting. No attacker authentication or user interaction is required.
What impact could successful exploitation have?
An attacker can recursively delete arbitrary directories on the server, potentially including the WordPress root directory. The reported impacts are integrity and availability loss; confidentiality impact is not indicated.
What can be done if the plugin cannot be patched immediately?
Disable the “Delete files from server after form submissions” setting. Exploitation is described as requiring that feature to be enabled.
How can administrators determine whether they are affected?
Check whether Super Forms is installed at version 6.3.316 or earlier and whether “Delete files from server after form submissions” is enabled. Sites meeting both conditions are affected according to the available information.