PT-2026-70887 · Strategy11 · Formidable Digital Signatures

·

CVE-2026-16230

·

Publicado

2026-08-11

·

Atualizado

2026-08-11

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item meta[field id][content] parameter alongside the delete saved image flag during the standard entry-creation POST flow on any form that accepts anonymous submissions.

Correção

Relative Path Traversal

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-16230

Produtos afetados

Formidable Digital Signatures