CVE-2026-17609: critical vulnerability in WebRehab Super Forms – Drag & Drop Form Builder
Super Forms <= 6.3.316 - Unauthenticated Arbitrary Directory Deletion via 'data[...][files][][subdir]' Parameter
Published
25Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 9.1
exploitation probability
—
observed exploitation
nono source reports it
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server, including the WordPress root directory. Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, though this is a documented and commonly-enabled feature.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Affected products
WebRehab · Super Forms – Drag & Drop Form BuilderRelated CVEs — WebRehab Super Forms – Drag & Drop Form Builder
In the same product, most dangerous first.
CVE-2026-14894CRITICALSuper Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)EPSS 5.1%CVE-2026-15896CRITICALSuper Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path ParameterEPSS 0.9%CVE-2026-15983HIGHSuper Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' ParameterEPSS 0.5%CVE-2026-15897HIGHSuper Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & LoginEPSS 0.3%CVE-2026-15989CRITICALSuper Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' ParameterEPSS 0.3%CVE-2026-17196HIGHSuper Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File Upload via 'extensions' Form Element AttributeEPSS —