Junglewise Threat Intelligence

CVE-2026-40769: Divi People Contact Form Extender arbitrary file deletion

CVE-2026-40769 · Severity: high · CVSS 8.6 · Published 2026-06-15

Executive brief

A vulnerability in a popular WordPress plugin used for enhancing Divi contact forms allows unauthorized individuals to delete files from the web server. This could lead to a complete website outage if critical system files are removed, potentially disrupting business operations and requiring a full site restoration. The flaw can be exploited remotely without needing any login credentials.

Technical details

The Contact Form Extender for Divi plugin (<= 1.0.6) contains an arbitrary file deletion vulnerability classified as CWE-22 (Path Traversal). The flaw allows an unauthenticated remote attacker to send specially crafted requests to delete files on the server. This occurs due to insufficient validation of user-supplied input used in file deletion operations, likely within the file upload or entry management components. Successful exploitation can result in the deletion of critical WordPress core files or configuration files, leading to a permanent Denial of Service (DoS). A patch is available in version 1.0.7.

Affected products

  • Divi People Contact Form Extender for Divi – Save Entries, File Upload & Country Code Field <= 1.0.6

Timeline

  • 2026-03-06: other: Reported by researcher babyhack(@OPCIA)
  • 2026-04-21: disclosed: Initial disclosure by Patchstack
  • 2026-06-15: advisory: NVD publication date

References