๐Ÿ” CVE Alert

CVE-2026-16230

CRITICAL 9.8

Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field

CVSS Score
9.8
EPSS Score
0.0%
EPSS Percentile
0th

The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved_image flag during the standard entry-creation POST flow on any form that accepts anonymous submissions.

CWE CWE-23
Vendor strategy11
Product formidable digital signatures
Published Aug 11, 2026
Last Updated Aug 11, 2026
Stay Ahead of the Next One

Get instant alerts for strategy11 formidable digital signatures

Be the first to know when new critical vulnerabilities affecting strategy11 formidable digital signatures are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

Strategy11 / Formidable Digital Signatures
0 โ‰ค 3.0.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wordfence.com: https://www.wordfence.com/threat-intel/vulnerabilities/id/c9a5f8ca-7efc-401b-8a93-07fbe7204dce?source=cve formidableforms.com: https://formidableforms.com/ formidableforms.com: https://formidableforms.com/changelog/digital-signature-forms-3-1/

Credits

Rafie Muhammad