Skip to content

BuildNot yet confirmed elsewhere1 publisher2 min readPublished

Super Forms' second critical flaw in 2026 lets a form submission delete WordPress directories

Super Forms CVE-2026-17609 (CVSS 9.1) lets unauthenticated visitors recursively delete server directories when file cleanup is enabled. Versions through 6.3.316 are affected, and 6.3.317 fixes it, a dev.to analysis says.

The Engineer · Build desk

How we use AISend a correction

Illustration accompanying Super Forms' second critical flaw in 2026 lets a form submission delete WordPress directories
Generated illustration
File-cleanup sites risk deletion; 6.3.317 fixes it How the Super Forms directory-deletion flaw reaches each group of site owners, and which version fixes each release line.

Exposure map: 13,000+ installs run the plugin; attacks need the file-cleanup setting on; job and support upload sites often enable it; small sites without backups face a business-ending loss; stable admins on 6.3.316 or earlier need 6.3.317; 6.4 beta admins need 6.4.008.

File-cleanup sites risk deletion; 6.3.317 fixes it
WhoHowKindClaim
Super Forms installsAn estimated 13,000+ active installations run the pluginexposure5
Sites with file cleanup enabledExploitation requires the 'Delete files from server after form submissions' setting to be turned onconstraint8
Upload-workflow sitesJob application and support ticket sites frequently enable the cleanup setting to avoid disk bloatexposure9
Small sites without backupsDeletion of the whole site, including files and uploads, is a business-ending eventcost16
Stable-line admins6.3.316 and earlier are affected; the fix is in 6.3.317decision20
6.4 beta adminsThe beta line received the same hardening in version 6.4.008decision12

What happened

  • The flaw was disclosed on October 8, 2026, and its record was updated on October 10, 2026.
  • The plugin has an estimated 13,000-plus active installations, according to the dev.to analysis.
  • In July 2026 researchers disclosed CVE-2026-14894, a critical unauthenticated upload flaw in the same plugin; attackers exploited it within days and security teams blocked more than 250,000 attempts.
  • The 6.3.317 release also fixes an unauthenticated file read, CVE-2026-28167, and an upload extension bypass, CVE-2026-17196.

Why it matters

  • exposure Sites that take uploads for job applications or support tickets frequently enable the cleanup setting, according to the analysis, so those sites are the ones most likely to meet the precondition.
  • cost For a small site without backups, the analysis calls deletion of the whole install a business-ending event, so the backup is the control that sets recovery cost.
  • contradiction The analysis urges patching on the plugin's mass-exploitation history, yet it confirms no public proof of concept and no CISA KEV listing, so the urgency rests on that history.
  • decision Admins on the 6.4 beta line need 6.4.008 and not 6.3.317, because the beta line was hardened under its own version number.

On a form submission, the browser sends the field data plus a JSON structure that says which fields were submitted and, for upload fields, where the files should go [17]. The submit_form handler is supposed to check that JSON against the form definition stored on the server [18]. In the vulnerable versions it fails to validate the attacker-controlled field declarations against the actual form schema [6]. A second check, a path guard meant to confine file operations inside the WordPress directory, can be bypassed trivially [7].

The gate is one administrator setting, "Delete files from server after form submissions" [8]. With it on, the analysis says an attacker with no account can recursively delete any directory, up to the entire WordPress installation [4]. We think switching the setting off is the faster control for a site that cannot update today, because it removes the precondition the analysis names.

The analysis gives the vector string as "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", with attack complexity low and no conditions beyond the enabled setting [11]. Confidentiality impact is none because the flaw does not read data, and the analysis says that is why the score is 9.1 and not 9.8 or higher [19]. Integrity and availability are both rated high [11].

Wordfence assigned the ID and reserved it on July 27, 2026 [15]. Disclosure came 73 days later, on October 8 [21].

The analysis tells admins to install the latest available release, since the vendor hardened a long list of other file-handling paths alongside this fix [14].

What to watch

  • Whether a public proof of concept appears or CVE-2026-17609 is added to CISA's KEV catalog; the analysis says neither has happened.
  • Whether exploit attempts against CVE-2026-17609 show up the way they did against CVE-2026-14894, which drew more than 250,000 blocked attempts.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence50
Adoption
Insufficient
Hype gap+15
Incentives
Insufficient
Confidence55
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    No public proof of concept for CVE-2026-17609 is confirmed and it is not in CISA's KEV catalog, but the analysis says the plugin has a proven history of fast mass exploitation.

  2. [2]

    CVE-2026-17609 is an unauthenticated arbitrary directory deletion flaw in the Super Forms - Drag & Drop Form Builder plugin, rated CVSS 9.1 (Critical).

    ReportedSupportedView cited source
  3. [3]

    CVE-2026-17609 was disclosed on October 8, 2026, and its record was updated on October 10, 2026.

    ReportedSupportedView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. dev.to

    1 article · October 11, 2026

    CVE-2026-17609: Super Forms WordPress Plugin Arbitrary Directory Deletion Vulnerability (CVSS 9.1) — Analysis & Mitigation

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories