Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-17609— Super Forms <= 6.3.316 - Unauthenticated Arbitrary Directory Deletion via 'data[...][files][][subdir]' Parameter

Quick assessment

Affected
WebRehab Super Forms – Drag & Drop Form Builder
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件 Super Forms – Drag & Drop Form Builder 在所有不超过 6.3.316 的版本中均存在任意目录删除漏洞,该漏洞可通过 submit_form 函数触发。此漏洞的成因在于:对攻击者可控的 JSON 字段声明与实际表单结构之间的验证不足,同时 ABSPATH(WordPress 根目录路径)检查机制失效——dirname() 函数可通过简单去除末尾斜杠轻易绕过该保护机制。这使得未经身份验证的攻击者能够递归删除服务器上的任意目录,包括 WordPress 的根

CVSS 9.1 · Critical
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-17609

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Super Forms <= 6.3.316 - Unauthenticated Arbitrary Directory Deletion via 'data[...][files][][subdir]' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary Directory Deletion in all versions up to, and including, 6.3.316 via the submit_form function. This is due to insufficient validation of attacker-controlled JSON field declarations against the actual form schema, combined with a non-effective ABSPATH guard that dirname() trivially bypasses by stripping the trailing slash. This makes it possible for unauthenticated attackers to recursively delete arbitrary directories on the server, including the WordPress root directory. Exploitation requires that an administrator has enabled the 'Delete files from server after form submissions' setting, though this is a documented and commonly-enabled feature.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
危险类型文件的不加限制上传
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WebRehab Super Forms – Drag & Drop Form Builder 0 ~ 6.3.316 -

II. Public POCs for CVE-2026-17609

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-17609

请登录查看更多情报信息。

Other References for CVE-2026-17609 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-17609

No comments yet


Leave a comment