2 vulnerabilities across 2 products scored HIGH or above on October 08, 2026.

  • ๐ŸŸ  HIGH: 2

๐ŸŸ  [HIGH] webrehab/super_forms_โ€“drag&_drop_form_builder

1 CVE | CVSS 3.1: 9.1 | AAS 9.9

  • cpe:2.3:a:webrehab:super_forms_drag_drop_form_builder:*:*:*:*:*:*:*:*

Super Forms โ€“ Drag & Drop Form Builder by webrehab has one critical vulnerability. CVE-2026-17609 carries a CVSS 3.1 score of 9.1 and allows unauthenticated attackers to recursively delete arbitrary directories on the server by exploiting insufficient validation of JSON field declarations in the submit_form function, combined with a trivially bypassable ABSPATH guard. All versions up to and including 6.3.316 are affected.

WordPress administrators running this form builder plugin should treat this as an urgent priority. The vulnerability requires no authentication to exploit, meaning any internet-facing site with this plugin installed is at risk of complete data loss through arbitrary directory deletion. Administrators should review the vendor’s patch at the referenced GitHub pull request and update immediately once a fixed version is available. If an update is not yet released, consider temporarily disabling the plugin until a patch is confirmed.

Vendor Advisory


๐ŸŸ  [HIGH] melapress/wp_2fa

1 CVE | CVSS 3.1: 8.8 | AAS 9.6

  • cpe:2.3:a:melapress:wp_2fa:*:*:*:*:*:*:*:*

Melapress WP 2FA, a widely used WordPress two-factor authentication plugin, has one high-severity vulnerability. CVE-2026-62142 carries a CVSS 3.1 score of 8.8 and is a cross-site request forgery flaw affecting all versions through 4.1.0, which could allow an attacker to trick an authenticated administrator into performing unintended actions on the plugin’s security-critical 2FA configuration.

WordPress administrators relying on WP 2FA for two-factor authentication should prioritize this update, as a CSRF vulnerability in a security plugin is particularly dangerous โ€” it could potentially be used to weaken or disable 2FA protections site-wide. Review the Patchstack advisory at the referenced link and update to a patched version as soon as one is available.

Vendor Advisory