PatchSiren cyber security CVE debrief
CVE-2026-17609 WebRehab CVE debrief
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server, including the WordPress root directory. Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, though this is a documented and commonly-enabled feature.
- Vendor
- WebRehab
- Product
- Super Forms – Drag & Drop Form Builder
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-08
- Original CVE updated
- 2026-10-08
- Advisory published
- 2026-10-08
- Advisory updated
- 2026-10-08
Who should care
Defenders responsible for WordPress installations with the Super Forms plugin should assess exposure and prioritize verification of the plugin version and configuration. This includes reviewing administrator settings and monitoring for suspicious activity. Security teams and vulnerability managers must ensure that Super Forms versions are up-to-date and that configurations are secure.
Why it matters
CVE-2026-17609 is a critical vulnerability in the Super Forms plugin for WordPress, allowing unauthenticated attackers to delete arbitrary directories. Defenders should prioritize verification of plugin versions, review administrator settings, and monitor for suspicious activity.
- Unauthenticated attackers can recursively delete arbitrary directories on the server, including the WordPress root directory.
- Exploitation requires administrator-enabled 'Delete files from server after form submissions' setting.
- Defenders must verify Super Forms plugin version and configuration to prevent exploitation.
- Monitoring for suspicious directory deletion activity is necessary to detect potential attacks.
Technical summary
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash.
Defensive priority
Defenders should prioritize verifying the Super Forms plugin version and configuration, reviewing administrator settings, and monitoring for suspicious directory deletion activity.
Recommended defensive actions
- Verify the Super Forms plugin version and configuration
- Review administrator settings for the 'Delete files from server after form submissions' setting
- Monitor for suspicious directory deletion activity
- Perform vulnerability scanning to identify potentially exposed systems
- Review system logs for signs of unauthorized directory deletion
- Implement additional monitoring for high-risk assets
- Track remediation progress and verify fixes
Evidence notes
The CVE record and source item provide details on the vulnerability, including the affected plugin, version 6.3.316, and exploitation requirements. Defenders should verify Super Forms plugin version and configuration to understand potential exposure. The 'Delete files from server after form submissions' setting must be enabled for exploitation. Evidence is limited to public CVE details and source item information.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-17609 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-17609
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-17609 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-17609
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Super Forms <= 6.3.316 - Unauthenticated Arbitrary Directory Deletion via 'data[...][files][][su
Unverified legacy reference
URL: https://raw.githubusercontent.com/CVEProject/cvelistV5/main/cves/2026/17xxx/CVE-2026-17609.json
cve_program_cvelist_v5
-
Source reference
Unverified legacy reference
URL: https://github.com/RensTillmann/super-forms/pull/205
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.