CVE-2026-17609 is a critical (CVSS 9.1) flaw in the Super Forms – Drag & Drop Form Builder plugin for WordPress, through version 6.3.316. According to the NVD description, it can let unauthenticated attackers recursively delete directories outside their intended scope on the server, potentially including the WordPress root. This only works on sites where an administrator has enabled the plugin's "Delete files from server after form submissions" setting.
What Is It
The flaw is an arbitrary directory deletion bug in the plugin's submit_form function. According to the NVD description, it has two causes:
- The plugin does not properly check attacker-controlled JSON field declarations against the form's actual schema.
- The plugin has an ABSPATH guard meant to keep deletions inside the WordPress install, but it does not work.
dirname()strips the trailing slash, which bypasses the check.
Together, these let an attacker recursively delete directories outside their intended scope. Wordfence, which assigned the CVE, mapped the weakness to CWE-434.
Why It Matters
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H. That means the attack works over the network, has low complexity, and needs no privileges or user interaction. Integrity and availability impact are both rated high. If an attacker deleted the WordPress root directory, the site would go completely offline.
There is one precondition. An administrator must have enabled the "Delete files from server after form submissions" setting. The CVE description says this is a documented and commonly enabled feature, so many installations may be exposed.
The CISA Known Exploited Vulnerabilities (KEV) catalog has no entry for CVE-2026-17609 in the supplied data, so active exploitation has not been confirmed. The NVD record has the status "Received" and was published on 2026-10-08.
What's Vulnerable
- Vendor: WebRehab
- Product: Super Forms – Drag & Drop Form Builder (WordPress plugin)
- Affected versions: all versions up to and including 6.3.316
- Required configuration: "Delete files from server after form submissions" enabled
Patch Status
The supplied records do not name a fixed version. The NVD references include a GitHub pull request on the Super Forms repository (RensTillmann/super-forms PR #205), which may contain the fix. The source data does not confirm whether it has been merged or released.
CISA has not set a required action because the flaw is not in KEV. Until a fixed release is confirmed, administrators running version 6.3.316 or earlier should:
- Check whether "Delete files from server after form submissions" is enabled, and consider turning it off.
- Watch the vendor and the Wordfence advisory for an updated plugin version.