BuildNot yet confirmed elsewhere1 publisher2 min readPublished
Super Forms' second critical flaw in 2026 lets a form submission delete WordPress directories
Super Forms CVE-2026-17609 (CVSS 9.1) lets unauthenticated visitors recursively delete server directories when file cleanup is enabled. Versions through 6.3.316 are affected, and 6.3.317 fixes it, a dev.to analysis says.
The Engineer · Build desk

Exposure map: 13,000+ installs run the plugin; attacks need the file-cleanup setting on; job and support upload sites often enable it; small sites without backups face a business-ending loss; stable admins on 6.3.316 or earlier need 6.3.317; 6.4 beta admins need 6.4.008.
- exposure Super Forms installs An estimated 13,000+ active installations run the plugin, claim 5
- constraint Sites with file cleanup enabled Exploitation requires the 'Delete files from server after form submissions' setting to be turned on, claim 8
- exposure Upload-workflow sites Job application and support ticket sites frequently enable the cleanup setting to avoid disk bloat, claim 9
- cost Small sites without backups Deletion of the whole site, including files and uploads, is a business-ending event, claim 16
- decision Stable-line admins 6.3.316 and earlier are affected; the fix is in 6.3.317, claim 20
- decision 6.4 beta admins The beta line received the same hardening in version 6.4.008, claim 12
| Who | How | Kind | Claim |
|---|---|---|---|
| Super Forms installs | An estimated 13,000+ active installations run the plugin | exposure | 5 |
| Sites with file cleanup enabled | Exploitation requires the 'Delete files from server after form submissions' setting to be turned on | constraint | 8 |
| Upload-workflow sites | Job application and support ticket sites frequently enable the cleanup setting to avoid disk bloat | exposure | 9 |
| Small sites without backups | Deletion of the whole site, including files and uploads, is a business-ending event | cost | 16 |
| Stable-line admins | 6.3.316 and earlier are affected; the fix is in 6.3.317 | decision | 20 |
| 6.4 beta admins | The beta line received the same hardening in version 6.4.008 | decision | 12 |
What happened
- The flaw was disclosed on October 8, 2026, and its record was updated on October 10, 2026.
- The plugin has an estimated 13,000-plus active installations, according to the dev.to analysis.
- In July 2026 researchers disclosed CVE-2026-14894, a critical unauthenticated upload flaw in the same plugin; attackers exploited it within days and security teams blocked more than 250,000 attempts.
- The 6.3.317 release also fixes an unauthenticated file read, CVE-2026-28167, and an upload extension bypass, CVE-2026-17196.
Why it matters
- exposure Sites that take uploads for job applications or support tickets frequently enable the cleanup setting, according to the analysis, so those sites are the ones most likely to meet the precondition.
- cost For a small site without backups, the analysis calls deletion of the whole install a business-ending event, so the backup is the control that sets recovery cost.
- contradiction The analysis urges patching on the plugin's mass-exploitation history, yet it confirms no public proof of concept and no CISA KEV listing, so the urgency rests on that history.
- decision Admins on the 6.4 beta line need 6.4.008 and not 6.3.317, because the beta line was hardened under its own version number.
On a form submission, the browser sends the field data plus a JSON structure that says which fields were submitted and, for upload fields, where the files should go [17]. The submit_form handler is supposed to check that JSON against the form definition stored on the server [18]. In the vulnerable versions it fails to validate the attacker-controlled field declarations against the actual form schema [6]. A second check, a path guard meant to confine file operations inside the WordPress directory, can be bypassed trivially [7].
The gate is one administrator setting, "Delete files from server after form submissions" [8]. With it on, the analysis says an attacker with no account can recursively delete any directory, up to the entire WordPress installation [4]. We think switching the setting off is the faster control for a site that cannot update today, because it removes the precondition the analysis names.
The analysis gives the vector string as "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H", with attack complexity low and no conditions beyond the enabled setting [11]. Confidentiality impact is none because the flaw does not read data, and the analysis says that is why the score is 9.1 and not 9.8 or higher [19]. Integrity and availability are both rated high [11].
Wordfence assigned the ID and reserved it on July 27, 2026 [15]. Disclosure came 73 days later, on October 8 [21].
The analysis tells admins to install the latest available release, since the vendor hardened a long list of other file-handling paths alongside this fix [14].
What to watch
- Whether a public proof of concept appears or CVE-2026-17609 is added to CISA's KEV catalog; the analysis says neither has happened.
- Whether exploit attempts against CVE-2026-17609 show up the way they did against CVE-2026-14894, which drew more than 250,000 blocked attempts.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence50
- Adoption
- Insufficient
- Hype gap+15
- Incentives
- Insufficient
- Confidence55
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
No public proof of concept for CVE-2026-17609 is confirmed and it is not in CISA's KEV catalog, but the analysis says the plugin has a proven history of fast mass exploitation.
- [2]
CVE-2026-17609 is an unauthenticated arbitrary directory deletion flaw in the Super Forms - Drag & Drop Form Builder plugin, rated CVSS 9.1 (Critical).
- [3]
CVE-2026-17609 was disclosed on October 8, 2026, and its record was updated on October 10, 2026.
- [4]
An attacker with no account on the site can recursively delete any directory on the server, including the entire WordPress installation.
- [5]
The Super Forms plugin has an estimated 13,000+ active installations.
- [6]
The plugin's submit_form function fails to properly validate attacker-controlled JSON field declarations against the actual form schema.
- [7]
A path guard meant to confine file operations inside the WordPress directory can be trivially bypassed.
- [8]
Exploitation requires that an administrator has enabled the plugin's "Delete files from server after form submissions" setting.
- [9]
The setting is a documented, commonly enabled feature; sites using Super Forms for job applications, support tickets or other file-upload workflows frequently turn it on to avoid disk bloat.
- [10]
In July 2026 researchers disclosed CVE-2026-14894, a critical unauthenticated file-upload flaw in the same plugin that attackers began exploiting within days; security teams ultimately blocked more than 250,000 exploit attempts against it.
- [11]
The CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H: network attack vector, low attack complexity with no special conditions beyond the enabled setting, no privileges or user interaction required, and high integrity and availability impact.
- [12]
The Super Forms 6.4 beta line received the same hardening in version 6.4.008.
- [13]
According to the vendor's security release notes, 6.3.317 also fixes an unauthenticated file read (CVE-2026-28167) and an upload extension bypass (CVE-2026-17196).
- [14]
The analysis advises updating to the latest available release rather than stopping at 6.3.317, because the vendor hardened a long list of other file-handling paths in the same release.
- [15]
CVE-2026-17609 was assigned by Wordfence and reserved on July 27, 2026.
- [16]
The analysis calls the deletion of a whole website, including files and uploads, a business-ending event for a small site without backups.
- [17]
When a visitor submits a Super Forms form, the browser sends the form data plus a JSON structure describing which fields were submitted and, for file-upload fields, where the uploaded files should go.
- [18]
The submit_form handler is supposed to check that JSON against the actual form definition stored on the server.
- [19]
Confidentiality impact is none because the flaw does not directly read data, which is why it scores 9.1 instead of 9.8 or higher.
- [20]
Super Forms 6.3.316 and earlier are affected, and the vendor's security release notes put the fix in 6.3.317 on the stable line.
- [21]
The CVE ID was reserved 73 days before disclosure.
Sources
1 independent publisher whose own reporting we read for this story.
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Topics
- Vulnerability DisclosureFollow
- Input validation flawsFollow
- WordPress Plugin SecurityFollow