Sceawere

Vulnerability Detail

CVE-2026-17609UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Super Forms Arbitrary Directory Deletion

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
3h ago
Vendor
WebRehab
Product
Super Forms – Drag & Drop Form Builder
Attack Type
CWE-434 Unrestricted Upload of File with Dangerous Type
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server, including the WordPress root directory. Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, though this is a documented and commonly-enabled feature.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-10-08T05:17:04.793Z",
  "pubdate": "2026-10-08T05:17:04.793Z",
  "executiveSummary": "The Super Forms – Drag & Drop Form Builder plugin for WordPress is susceptible to an Arbitrary Directory Deletion vulnerability, identified in all versions up to and including 6.3.316. This critical security flaw permits unauthenticated attackers to execute arbitrary directory removal on the underlying server, including the potential for recursive deletion of the entire WordPress root directory.\nThe vulnerability originates from a failure in input validation within the submit_form function, which processes user-controlled JSON field declarations without verifying them against the defined form schema. Furthermore, security controls intended to constrain file system operations via ABSPATH are rendered ineffective through the use of dirname(), which facilitates path traversal by manipulating trailing slashes.\nWhile exploitation is contingent upon an administrator enabling the 'Delete files from server after form submissions' feature, this setting is a standard, frequently utilized component of the plugin. Given the severity of the impact, which ranges from critical data loss to complete service disruption and site compromise, the risk level is high. Unauthenticated attackers can leverage this flaw to destabilize or destroy the WordPress installation, making immediate remediation essential for affected environments.",
  "technicalDetails": "The vulnerability resides within the submit_form function of the Super Forms – Drag & Drop Form Builder plugin. The mechanism responsible for file deletion fails to implement rigorous server-side validation for incoming JSON data payloads. Specifically, the function accepts attacker-supplied file paths as part of the form submission process and relies on these inputs to perform file system cleanup operations without ensuring the paths remain within intended directories.\nThe primary technical failure is the circumvention of the ABSPATH check. The plugin developers attempted to use ABSPATH as a protective guard to define the boundaries of file deletion operations; however, the subsequent application of the dirname() function bypasses this security check. By stripping the trailing slash from the path, the logic incorrectly validates directory strings, allowing the traversal sequences to escape the designated upload directory.\nThe attack flow follows a structured trajectory: First, an attacker identifies a form where the 'Delete files from server after form submissions' functionality is active. The attacker then crafts a malicious JSON payload designed to define a field that targets a specific directory path on the server filesystem. Upon submission, the server-side code processes the user-controlled input, bypassing the insufficient path validation.\nBecause the sanitization logic does not normalize the path or verify that the resultant string resides within the expected sub-directory, the filesystem operation executes with the permissions of the web server user. By providing a path pointing to sensitive directories—such as the WordPress root directory—the server proceeds to perform a recursive deletion of the targeted directory and its contents. This allows for an unauthenticated user to achieve total deletion of site files, plugins, and themes, effectively resulting in a permanent denial of service or the complete wipe of the application environment.\nThis vulnerability is classified as critical because it requires no prior authentication or administrative privileges to trigger, provided the aforementioned plugin configuration is active. The lack of validation on the JSON field declarations makes this an ideal vector for remote, unauthorized destructive actions."
}
CVE-2026-17609: Super Forms Arbitrary Directory Deletion (CRITICAL Severity, CVSS: 9.1) | Sceawere