Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in the Super Forms WordPress plugin that allows unauthenticated attackers to delete arbitrary directories on the server, potentially including the entire WordPress installation. This issue arises from insufficient validation of user-supplied data within the form submission process, even with a common administrator setting enabled. The primary concern is to confirm if this plugin is in use and if the specific configuration is active, as exploitation could lead to significant disruption.
- Attackers can delete server files and folders.
- A common setting makes this plugin a target.
- Confirm plugin use and its specific configuration.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by sending specially crafted data to a WordPress site that uses the Super Forms plugin. If an administrator has enabled the setting to delete files after form submissions, an unauthenticated attacker can trick the plugin into deleting arbitrary directories on the server. This could potentially lead to the deletion of critical website files, including the entire WordPress installation.
- Requires a specific plugin setting enabled.
- Triggered by submitting a manipulated form.
- Risk of arbitrary directory deletion.
Live Threat
Current exploitation, exposure, and threat context
Unauthenticated attackers could delete arbitrary directories on a WordPress server, including the entire WordPress root, if the 'Delete files from server after form submissions' setting is enabled. This setting is a documented and commonly-enabled feature for the Super Forms plugin.
- Arbitrary directory deletion.
- Via insufficient JSON validation.
- Complete site and data loss.
Operational Fix
Recommended remediation, mitigation, and detection steps
This critical vulnerability in a WordPress form builder plugin allows unauthenticated attackers to delete arbitrary directories. Action should be coordinated by the application or platform team responsible for the WordPress instance, with support from the security team for exposure assessment and the vendor-management team if the plugin is managed through a third party. The immediate first step is to identify all instances of the affected plugin, confirm their reachability and business criticality, and then prioritize remediation based on this risk assessment.
- WordPress application or platform owners.
- Verify plugin instances and site configuration.
- Plan remediation based on identified risk.