chiprook
← Security
SecurityOctober 12, 2026, 03:01

CVE-2026-17609: Critical Arbitrary Directory Deletion in Super Forms WordPress Plugin

A critical vulnerability, CVE-2026-17609 (CVSS 9.1), in the Super Forms – Drag & Drop Form Builder plugin for WordPress allows unauthenticated attackers to recursively delete arbitrary directories on the server. Versions 6.3.316 and earlier are affected; the flaw is fixed in 6.3.317.

CVE-2026-17609: Critical Arbitrary Directory Deletion in Super Forms WordPress Plugin
#WordPress#SuperForms
Read next
Security

Hackers exploit Ninja Forms and WPC Product Bundles plugin flaws on WordPress

Security

Four WordPress plugins hit by CVSS 9.8 auth bypass flaws

Security

CVE-2026-12227: Critical unauthenticated LFI in Visual Composer WordPress plugin

Security

Forminator WordPress plugin hit by 9.1-severity vulnerability