External risk intelligence

Super Forms Arbitrary Directory Deletion Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.1)

CVE-2026-17609

The vulnerability exists in a WordPress form builder plugin, which is typically deployed as part of public-facing web applications. Because the plugin functionality is intended to handle form submissions from site visitors, the vulnerable code path is inherently exposed to the internet. While it requires a specific setting to be enabled, such configurations are common for this type of software.

Unrestricted File Upload

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in the Super Forms WordPress plugin that allows unauthenticated attackers to delete arbitrary directories on the server, potentially including the entire WordPress installation. This issue arises from insufficient validation of user-supplied data within the form submission process, even with a common administrator setting enabled. The primary concern is to confirm if this plugin is in use and if the specific configuration is active, as exploitation could lead to significant disruption.

  • Attackers can delete server files and folders.
  • A common setting makes this plugin a target.
  • Confirm plugin use and its specific configuration.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending specially crafted data to a WordPress site that uses the Super Forms plugin. If an administrator has enabled the setting to delete files after form submissions, an unauthenticated attacker can trick the plugin into deleting arbitrary directories on the server. This could potentially lead to the deletion of critical website files, including the entire WordPress installation.

  • Requires a specific plugin setting enabled.
  • Triggered by submitting a manipulated form.
  • Risk of arbitrary directory deletion.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could delete arbitrary directories on a WordPress server, including the entire WordPress root, if the 'Delete files from server after form submissions' setting is enabled. This setting is a documented and commonly-enabled feature for the Super Forms plugin.

  • Arbitrary directory deletion.
  • Via insufficient JSON validation.
  • Complete site and data loss.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in a WordPress form builder plugin allows unauthenticated attackers to delete arbitrary directories. Action should be coordinated by the application or platform team responsible for the WordPress instance, with support from the security team for exposure assessment and the vendor-management team if the plugin is managed through a third party. The immediate first step is to identify all instances of the affected plugin, confirm their reachability and business criticality, and then prioritize remediation based on this risk assessment.

  • WordPress application or platform owners.
  • Verify plugin instances and site configuration.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Super Forms plugin for WordPress?

Super Forms is a drag-and-drop form builder plugin used within WordPress to create, manage, and process user-submitted data. It often includes features that handle file uploads or management on the server, which are frequently integrated into contact forms, registration pages, or other public-facing data collection points.

What does arbitrary directory deletion mean for CVE-2026-17609?

This refers to an Improper Unrestricted Upload of File with Dangerous Type weakness, categorized as CWE-434. In this specific context, it means an attacker can bypass security checks to trick the plugin into deleting folders on your web server. Because the plugin processes these requests with high privileges, it can remove critical system directories, potentially causing total site failure.

How is the directory deletion vulnerability triggered?

An attacker triggers this by sending a specially crafted form submission containing malicious JSON data. This process only succeeds if the site administrator has explicitly enabled the 'Delete files from server after form submissions' feature in the plugin settings. If that specific option is disabled, the vulnerable code path that processes these deletion commands remains inactive.

Why should I care about this vulnerability?

According to Halo Surface Signal, this vulnerability is considered a high priority because the plugin is designed for public-facing web applications. Since the software is meant to accept submissions from internet users, the entry point for an attack is inherently exposed, making it easier for an unauthenticated user to attempt the deletion process remotely.

What are the first steps to secure my WordPress site?

Start by identifying all instances of the Super Forms plugin across your WordPress environment. Once located, check the plugin settings to see if the 'Delete files from server after form submissions' option is currently enabled. If it is, consider disabling this feature immediately while you work with your team to determine the next steps for updates or remediation.

References