CVE-2026-17609: fallo crítico en WebRehab Super Forms – Drag & Drop Form Builder
Super Forms <= 6.3.316 - Unauthenticated Arbitrary Directory Deletion via 'data[...][files][][subdir]' Parameter
Publicada el
25Vexday Risk Score
Sin señal de explotación. Ningún artefacto público de explotación conocido hasta ahora.
ssvc Trackcvss 9.1
probabilidad de explotación
—
explotación observada
noninguna fuente lo reporta
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server, including the WordPress root directory. Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, though this is a documented and commonly-enabled feature.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Productos afectados
WebRehab · Super Forms – Drag & Drop Form BuilderCVEs relacionadas — WebRehab Super Forms – Drag & Drop Form Builder
En el mismo producto, de las más peligrosas a las menos.
CVE-2026-14894CRITICALSuper Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)EPSS 5.1%CVE-2026-15896CRITICALSuper Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path ParameterEPSS 0.9%CVE-2026-15983HIGHSuper Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' ParameterEPSS 0.5%CVE-2026-15897HIGHSuper Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & LoginEPSS 0.3%CVE-2026-15989CRITICALSuper Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' ParameterEPSS 0.3%CVE-2026-17196HIGHSuper Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File Upload via 'extensions' Form Element AttributeEPSS —