The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting — combined with the `super_submit_form` handler's `submit_form` function passing the attacker-controlled `files[].subdir` value from `$_POST['data']` directly into `SUPER_Common::delete_dir()` without sanitization, and a trivially bypassed `ABSPATH` guard that a `subdir` value of `wp-config.php` defeats because `dirname(realpath(ABSPATH . $subdir))` resolves to the WordPress root while the naive `ABSPATH !== $dir` string check fails to match due to a trailing-slash mismatch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recursively delete arbitrary files and director
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-15983 exposes a critical vulnerability in the Super Forms – Drag & Drop Form Builder WordPress plugin (versions up to 6.3.316) that allows low-privileged Subscriber-level users to arbitrarily delete files and directories on affected servers. The vulnerability stems from two compounding weaknesses: the `super_save_form` AJAX handler lacks capability checks, enabling any authenticated user to modify form settings, and the `super_submit_form` handler's `submit_form` function fails to properly validate the attacker-controlled `files[].subdir` parameter. This combination permits attackers to manipulate file deletion operations by specifying arbitrary directory paths. Website administrators running WordPress installations with this plugin are at significant risk, particularly sites with open registration policies that allow subscribers to create accounts, as the attack requires only basic authentication.
While this CVE currently lacks mapped MITRE ATT&CK techniques, Casky's security skills powered by Claude AI would detect attack patterns consistent with Impact techniques, specifically T1485 (Data Destruction) and T1561 (Disk Wipe), through behavioral analysis of AJAX handler invocations combined with filesystem operations. Practitioners using Casky would observe findings highlighting: unauthorized capability usage in WordPress hooks, suspicious form parameter manipulation targeting file path variables, and anomalous filesystem deletion patterns tied to unauthenticated or low-privilege user contexts. Claude's extended reasoning would correlate the absence of nonce validation and capability checks in AJAX handlers with elevated risk patterns, surfacing this as a privilege escalation leading to destructive file operations — enabling security teams to identify compromised form configurations and malicious submission attempts before filesystem damage occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-15983. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation