CRITICALVulnerability
Verified
Global
NVD CRITICAL: CVE-2026-16230 — The Formidable Digital Signatures plugin for WordPress is vulnerable to file del...
·Source: NIST NVD
Updated:
Executive Summary
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved
Analysis
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved_image flag during the standard entry-creation POST flow on any form that accepts anonymous submissions. CVSS Score: 9.8. Published: 2026-08-11T20:17:27.133.