CVE-2026-17609: Critical Arbitrary Directory Deletion in Super Forms WordPress Plugin
A critical vulnerability, CVE-2026-17609 (CVSS 9.1), in the Super Forms – Drag & Drop Form Builder plugin for WordPress allows unauthenticated attackers to recursively delete arbitrary directories on the server. Versions 6.3.316 and earlier are affected; the flaw is fixed in 6.3.317.
- CVE-2026-17609 is rated CVSS 9.1 (Critical)
- Affects versions 6.3.316 and earlier; fixed in 6.3.317
- Exploitable unauthenticated when file-deletion setting is enabled
- Plugin has over 13,000 active installations
Read next
Security