CRITICAL 9.8 NVD
CVE-2026-16230
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in al
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved_image flag during the standard entry-creation POST flow on any form that accepts anonymous submissions.
References
- https://formidableforms.com/
- https://formidableforms.com/changelog/digital-signature-forms-3-1/
- https://www.wordfence.com/threat-intel/vulnerabilities/id/c9a5f8ca-7efc-401b-8a93-07fbe720
This critical severity vulnerability with a CVSS score of 9.8 was published on 2026-08-11 via NVD.
Risk Timeline
CVE Disclosed2026-08-11 · -1 days ago
Remediation Resources
Analysis & PoC
formidableforms.com/
vulnfeed aggregates 10022 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.