PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-15983 WebRehab CVE debrief

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion. Authenticated attackers with Subscriber-level access can delete arbitrary files and directories, potentially leading to full site takedown and remote code execution. This vulnerability exists in all versions up to, and including, 6.3.316 of the plugin. The issue arises from the `super_save_form` AJAX handler's lack of capability checks and the `super_submit_form` handler's unsanitized use of the `files[].subdir` value from `$_POST['data']`. Immediate action is required to prevent exploitation.

Vendor
WebRehab
Product
Super Forms – Drag & Drop Form Builder
CVSS
HIGH 8.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-01
Original CVE updated
2026-10-03
Advisory published
2026-10-01
Advisory updated
2026-10-03

Who should care

WordPress administrators and users with Subscriber-level access and above should assess exposure and take immediate action to prevent potential exploitation. This includes reviewing the plugin's current version, updating to the latest version if necessary, and implementing additional security measures to protect against potential remote code execution.

Why it matters

CVE-2026-15983 is a high-severity vulnerability in the Super Forms – Drag & Drop Form Builder plugin for WordPress, allowing authenticated attackers with Subscriber-level access to delete arbitrary files and directories, potentially leading to full site takedown and remote code execution. Immediate action is required to prevent exploitation.

  • Potential full site takedown due to arbitrary file and directory deletion.
  • Possible remote code execution if critical files such as `wp-config.php` are removed and the site is subsequently re-installed by another party.
  • Increased risk of data loss and unauthorized access due to the vulnerability's exploitation.
  • Need for immediate patching or mitigation to prevent exploitation.

Technical summary

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting — combined with the `super_submit_form` handler's `submit_form` function passing the attacker-controlled `files[].subdir` value from `$_POST['data']` directly into `SUPER_Common::delete_dir()` without sanitization, and a trivially bypassed `ABSPATH` guard that a `subdir` value of `wp-config.php` defeats because `dirname(realpath(ABSPATH . $subdir))` resolves to the WordPress root while the naive `ABSPATH !== $dir` string check fails to match due to a trailing-slash mismatch.

Defensive priority

High

Recommended defensive actions

  • Immediately update the Super Forms – Drag & Drop Form Builder plugin to the latest version.
  • Restrict access to the plugin's AJAX handlers to prevent unauthorized use.
  • Monitor server logs for suspicious file deletion activities.
  • Implement additional security measures to protect against potential remote code execution.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability exists in the Super Forms – Drag & Drop Form Builder plugin for WordPress, versions up to and including 6.3.316. The issue arises from the `super_save_form` AJAX handler's lack of capability checks and the `super_submit_form` handler's unsanitized use of the `files[].subdir` value from `$_POST['data']`.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-15983 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-15983

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-15983 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15983

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.