CVE-2026-15983 - Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' Parameter
CVE ID :CVE-2026-15983 Published : Oct. 1, 2026, 8:28 a.m. | 48 minutes ago Description :The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX...