PT-2026-70887 · Strategy11 · Formidable Digital Signatures

·

CVE-2026-16230

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item meta[field id][content] parameter alongside the delete saved image flag during the standard entry-creation POST flow on any form that accepts anonymous submissions.

Fix

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-16230

Affected Products

Formidable Digital Signatures