CVE-2026-16230: STRATEGY11 Formidable Digital Signatures
Critical severity, CVSS 9.8. EPSS: 0.7% chance of exploitation in the next 30 days.
The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved_image flag during the standard entry-creation POST flow on any form that accepts anonymous submissions.
Affected products
- STRATEGY11 Formidable Digital Signatures: up to and including 3.0.6
Published 2026-08-11. Last modified 2026-08-12.