<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Remote-Deletion - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/remote-deletion/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 08 Oct 2026 06:50:18 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/remote-deletion/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Arbitrary Directory Deletion in Super Forms WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-10-super-forms-rce/</link><pubDate>Thu, 08 Oct 2026 06:50:18 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-super-forms-rce/</guid><description>Unauthenticated attackers can achieve arbitrary recursive directory deletion in Super Forms versions 6.3.316 and earlier by exploiting improper path validation in the submit_form function.</description><content:encoded><![CDATA[<p>The Super Forms - Drag &amp; Drop Form Builder plugin for WordPress (versions &lt;= 6.3.316) is vulnerable to an arbitrary directory deletion vulnerability. The flaw exists within the submit_form function, where insufficient validation of JSON field declarations allows for path manipulation. Attackers can bypass the ABSPATH security guard by using the dirname() function to strip trailing slashes, effectively traversing the filesystem. If an administrator has enabled the 'Delete files from server after form submissions' setting, an unauthenticated attacker can recursively delete arbitrary directories, including the entire WordPress installation. This vulnerability poses a severe risk to service availability and data integrity for any WordPress site utilizing this plugin with the specific administrative setting enabled.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker identifies a WordPress installation running a vulnerable version of the Super Forms plugin (&lt;= 6.3.316).</li>
<li>Attacker verifies the plugin's 'Delete files from server after form submissions' setting is active, commonly found in plugin configurations.</li>
<li>Attacker crafts a malicious JSON payload targeting the submit_form function.</li>
<li>Attacker includes a directory path string designed to bypass the ABSPATH security guard via dirname() behavior.</li>
<li>Attacker sends an HTTP POST request to the plugin's submission endpoint containing the crafted JSON.</li>
<li>The application parses the malicious JSON and fails to validate the directory path against the intended schema.</li>
<li>The application executes the recursive deletion command on the provided target path.</li>
<li>Final objective is achieved as the target directory (e.g., WordPress root) is deleted from the server.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in the recursive deletion of arbitrary directories on the host server. If the WordPress root directory is targeted, it results in complete application destruction and permanent data loss for the affected site. As the plugin is a popular form builder, numerous WordPress deployments globally are potentially at risk.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Immediately upgrade the Super Forms plugin to the latest available patched version.</li>
<li>Disable the 'Delete files from server after form submissions' feature in the Super Forms configuration if an immediate update is not possible.</li>
<li>Audit existing form submissions and plugin logs for any unexpected HTTP POST requests directed at the submit_form endpoint that contain directory traversal patterns (e.g., '../').</li>
<li>Ensure regular off-site backups are maintained to recover from potential data destruction events.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>vulnerability</category><category>remote-deletion</category><category>web-application</category></item></channel></rss>