Cyber & AI intelligence
Wasteland.
Briefs indexed3056
Issues31
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-17609 2026-10-08

Super Forms WordPress Plugin Flaw Lets Unauthenticated Attackers Delete Server Directories (CVE-2026-17609)

"CVE-2026-17609 is a critical (CVSS 9.1) flaw in the Super Forms – Drag & Drop Form Builder plugin for WordPress, through version 6.3.316. According to the NVD description, it can let unauthenticated attackers…"

CVE-2026-17609 is a critical (CVSS 9.1) flaw in the Super Forms – Drag & Drop Form Builder plugin for WordPress, through version 6.3.316. According to the NVD description, it can let unauthenticated attackers recursively delete directories outside their intended scope on the server, potentially including the WordPress root. This only works on sites where an administrator has enabled the plugin's "Delete files from server after form submissions" setting.

What Is It

The flaw is an arbitrary directory deletion bug in the plugin's submit_form function. According to the NVD description, it has two causes:

Together, these let an attacker recursively delete directories outside their intended scope. Wordfence, which assigned the CVE, mapped the weakness to CWE-434.

Why It Matters

The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H. That means the attack works over the network, has low complexity, and needs no privileges or user interaction. Integrity and availability impact are both rated high. If an attacker deleted the WordPress root directory, the site would go completely offline.

There is one precondition. An administrator must have enabled the "Delete files from server after form submissions" setting. The CVE description says this is a documented and commonly enabled feature, so many installations may be exposed.

The CISA Known Exploited Vulnerabilities (KEV) catalog has no entry for CVE-2026-17609 in the supplied data, so active exploitation has not been confirmed. The NVD record has the status "Received" and was published on 2026-10-08.

What's Vulnerable

Patch Status

The supplied records do not name a fixed version. The NVD references include a GitHub pull request on the Super Forms repository (RensTillmann/super-forms PR #205), which may contain the fix. The source data does not confirm whether it has been merged or released.

CISA has not set a required action because the flaw is not in KEV. Until a fixed release is confirmed, administrators running version 6.3.316 or earlier should:

Sources