Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-16230: Formidable Digital Signatures <= 3.0.6 - Unauthenticated File Deletion

CVE-2026-16230 · published 23 days ago
Summary

An attacker can delete files on your server without needing a password. This affects the Formidable Digital Signatures plugin for WordPress. To fix this, update the plugin to version 3.0.7 or later.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
strategy11 formidable digital signatures <= 3.0.6
Original advisory text
Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved_image flag during the standard entry-creation POST flow on any form that accepts anonymous submissions.
Severity
9.8 Critical
CVSS 3.1: 9.8 (NVD)
Exploitation
EPSS <1%
Type
CWE-23Relative Path Traversal
Timeline
Published11 Aug 2026
Updated3 Sep 2026
First seen11 Aug 2026
Sources
CVE-2026-16230 · MITRE
Monitor software like this
Free during beta