Junglewise Threat Intelligence

CVE-2026-16230: Formidable Forms Digital Signatures arbitrary file deletion

CVE-2026-16230 · Severity: critical · CVSS 9.8 · Published 2026-08-11

Executive brief

The Formidable Digital Signatures plugin for WordPress, used to add digital signature capture to forms, is vulnerable to unauthorized file deletion. An attacker can delete arbitrary files on a web server by sending a specially crafted request to any publicly accessible form that accepts anonymous submissions, without needing to log in or have any special permissions.

Technical details

The vulnerability is a path traversal / arbitrary file deletion flaw in the delete_file function of the Formidable Digital Signatures plugin (versions up to 3.0.6). The root cause is insufficient validation of the file path supplied via the item_meta[field_id][content] parameter during form submission. Unauthenticated attackers can exploit this by sending a POST request to any form with the delete_saved_image flag set and a malicious filename, allowing deletion of any server file accessible to the WordPress process. The vulnerability has been patched in version 3.1, which adds validation to ensure only signature files associated with the active entry can be deleted. No evidence of in-the-wild exploitation exists at this time.

Affected products

  • Formidable Forms Digital Signatures up to and including 3.0.6

Timeline

  • 2026-08-11: disclosed
  • 2026-08-04: patched: Patch released in version 3.1

References