---
id: CVE-2026-15983
title: >-
  The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable
  to Arbitrary File/Directory Deletion in all versions up to, and including,
  6.3.316
summary: >-
  The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable
  to Arbitrary File/Directory Deletion in all versions up to, and including,
  6.3.316. This is due to the `super_save_form` AJAX handler performing no
  capability …
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H'
cwe:
  - CWE-73
vendor: WebRehab
product: Super Forms – Drag & Drop Form Builder
affected:
  - super_forms_drag_drop_form_builder <= 6.3.316
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T09:17:09.223'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15983'
references:
  - url: 'https://github.com/RensTillmann/super-forms/pull/205'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/25704473-1200-49df-aa16-9a9558bb4844?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T09:41:14.155Z'
---

## Overview

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting — combined with the `super_submit_form` handler's `submit_form` function passing the attacker-controlled `files[].subdir` value from `$_POST['data']` directly into `SUPER_Common::delete_dir()` without sanitization, and a trivially bypassed `ABSPATH` guard that a `subdir` value of `wp-config.php` defeats because `dirname(realpath(ABSPATH . $subdir))` resolves to the WordPress root while the naive `ABSPATH !== $dir` string check fails to match due to a trailing-slash mismatch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recursively delete arbitrary files and directories on the server, up to and including the entire WordPress installation, resulting in full site takedown and potential remote code execution if critical files such as `wp-config.php` are removed and the site is subsequently re-installed by another party.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
