CVE-2026-17609: Super Forms <= 6.3.316 - Unauthenticated Arbitrary Directory Deletion via 'data[...][files][][subdir]' Parameter

Published Oct 8, 2026
·
Updated

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submitform function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server, including the WordPress root directory. Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, though this is a documented and commonly-enabled feature.

Affected Software

1 affected component
Super Forms Super Forms – Drag & Drop Form Builder<=6.3.316

Event History

Oct 8, 2026
CVE Published
via MITRE·04:28 AM
Data Sourced
via MITRE·04:28 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed to unauthenticated exploitation?

WordPress sites using Super Forms versions up to and including 6.3.316 are exposed if an administrator has enabled the “Delete files from server after form submissions” setting. No attacker authentication or user interaction is required.

2

What impact could successful exploitation have?

An attacker can recursively delete arbitrary directories on the server, potentially including the WordPress root directory. The reported impacts are integrity and availability loss; confidentiality impact is not indicated.

3

What can be done if the plugin cannot be patched immediately?

Disable the “Delete files from server after form submissions” setting. Exploitation is described as requiring that feature to be enabled.

4

How can administrators determine whether they are affected?

Check whether Super Forms is installed at version 6.3.316 or earlier and whether “Delete files from server after form submissions” is enabled. Sites meeting both conditions are affected according to the available information.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203