PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-17609 WebRehab CVE debrief

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server, including the WordPress root directory. Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, though this is a documented and commonly-enabled feature.

Vendor
WebRehab
Product
Super Forms – Drag & Drop Form Builder
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-08
Original CVE updated
2026-10-08
Advisory published
2026-10-08
Advisory updated
2026-10-08

Who should care

Defenders responsible for WordPress installations with the Super Forms plugin should assess exposure and prioritize verification of the plugin version and configuration. This includes reviewing administrator settings and monitoring for suspicious activity. Security teams and vulnerability managers must ensure that Super Forms versions are up-to-date and that configurations are secure.

Why it matters

CVE-2026-17609 is a critical vulnerability in the Super Forms plugin for WordPress, allowing unauthenticated attackers to delete arbitrary directories. Defenders should prioritize verification of plugin versions, review administrator settings, and monitor for suspicious activity.

  • Unauthenticated attackers can recursively delete arbitrary directories on the server, including the WordPress root directory.
  • Exploitation requires administrator-enabled 'Delete files from server after form submissions' setting.
  • Defenders must verify Super Forms plugin version and configuration to prevent exploitation.
  • Monitoring for suspicious directory deletion activity is necessary to detect potential attacks.

Technical summary

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash.

Defensive priority

Defenders should prioritize verifying the Super Forms plugin version and configuration, reviewing administrator settings, and monitoring for suspicious directory deletion activity.

Recommended defensive actions

  • Verify the Super Forms plugin version and configuration
  • Review administrator settings for the 'Delete files from server after form submissions' setting
  • Monitor for suspicious directory deletion activity
  • Perform vulnerability scanning to identify potentially exposed systems
  • Review system logs for signs of unauthorized directory deletion
  • Implement additional monitoring for high-risk assets
  • Track remediation progress and verify fixes

Evidence notes

The CVE record and source item provide details on the vulnerability, including the affected plugin, version 6.3.316, and exploitation requirements. Defenders should verify Super Forms plugin version and configuration to understand potential exposure. The 'Delete files from server after form submissions' setting must be enabled for exploitation. Evidence is limited to public CVE details and source item information.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-17609 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-17609

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-17609 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17609

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.