Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.8
CVE-2026-16230: Formidable Digital Signatures <= 3.0.6 - Unauthenticated File Deletion
CVE-2026-16230 · published 23 days ago
Summary
An attacker can delete files on your server without needing a password. This affects the Formidable Digital Signatures plugin for WordPress. To fix this, update the plugin to version 3.0.7 or later.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| strategy11 | formidable digital signatures | <= 3.0.6 |
Original advisory text
Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved_image flag during the standard entry-creation POST flow on any form that accepts anonymous submissions.
Severity
9.8
Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-23Relative Path Traversal
Timeline
Published11 Aug 2026
Updated3 Sep 2026
First seen11 Aug 2026
Monitor software like this
Free during beta