PatchSiren cyber security CVE debrief
CVE-2026-15983 WebRehab CVE debrief
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion. Authenticated attackers with Subscriber-level access can delete arbitrary files and directories, potentially leading to full site takedown and remote code execution. This vulnerability exists in all versions up to, and including, 6.3.316 of the plugin. The issue arises from the `super_save_form` AJAX handler's lack of capability checks and the `super_submit_form` handler's unsanitized use of the `files[].subdir` value from `$_POST['data']`. Immediate action is required to prevent exploitation.
- Vendor
- WebRehab
- Product
- Super Forms – Drag & Drop Form Builder
- CVSS
- HIGH 8.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-01
- Original CVE updated
- 2026-10-03
- Advisory published
- 2026-10-01
- Advisory updated
- 2026-10-03
Who should care
WordPress administrators and users with Subscriber-level access and above should assess exposure and take immediate action to prevent potential exploitation. This includes reviewing the plugin's current version, updating to the latest version if necessary, and implementing additional security measures to protect against potential remote code execution.
Why it matters
CVE-2026-15983 is a high-severity vulnerability in the Super Forms – Drag & Drop Form Builder plugin for WordPress, allowing authenticated attackers with Subscriber-level access to delete arbitrary files and directories, potentially leading to full site takedown and remote code execution. Immediate action is required to prevent exploitation.
- Potential full site takedown due to arbitrary file and directory deletion.
- Possible remote code execution if critical files such as `wp-config.php` are removed and the site is subsequently re-installed by another party.
- Increased risk of data loss and unauthorized access due to the vulnerability's exploitation.
- Need for immediate patching or mitigation to prevent exploitation.
Technical summary
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting — combined with the `super_submit_form` handler's `submit_form` function passing the attacker-controlled `files[].subdir` value from `$_POST['data']` directly into `SUPER_Common::delete_dir()` without sanitization, and a trivially bypassed `ABSPATH` guard that a `subdir` value of `wp-config.php` defeats because `dirname(realpath(ABSPATH . $subdir))` resolves to the WordPress root while the naive `ABSPATH !== $dir` string check fails to match due to a trailing-slash mismatch.
Defensive priority
High
Recommended defensive actions
- Immediately update the Super Forms – Drag & Drop Form Builder plugin to the latest version.
- Restrict access to the plugin's AJAX handlers to prevent unauthorized use.
- Monitor server logs for suspicious file deletion activities.
- Implement additional security measures to protect against potential remote code execution.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability exists in the Super Forms – Drag & Drop Form Builder plugin for WordPress, versions up to and including 6.3.316. The issue arises from the `super_save_form` AJAX handler's lack of capability checks and the `super_submit_form` handler's unsanitized use of the `files[].subdir` value from `$_POST['data']`.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-15983 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-15983
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-15983 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-15983
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/RensTillmann/super-forms/pull/205
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.