CVE-2026-16230

Formidable Digital Signatures <= 3.0.6 - Unauthenticated Arbitrary File Deletion via Signature Field

The Formidable Digital Signatures plugin for WordPress is vulnerable to file deletion due to insufficient file path validation in the delete_file function in all versions up to, and including, 3.0.6. This makes it possible for unauthenticated attackers to delete files on the server by supplying an attacker-controlled filename in the item_meta[field_id][content] parameter alongside the delete_saved_image flag during the standard entry-creation POST flow on any form that accepts anonymous submissions.


We have discovered 931 live websites that are affected by CVE-2026-16230.

Run a Free Instant Scan




Affected Software

Product  Formidable Forms
Category Wordpress Plugins
Vulnerable Domains931 live websites (1.38% of Formidable Forms install base)
Vulnerable Versions
  • from 0 through 3.0.6
Vulnerable Versions Count38 versions ( 15% of all versions)


Common Weakness Enumeration

CWE-23 Relative Path Traversal



Details

  • Published - Aug 11, 2026
  • Updated - Aug 11, 2026

Credits

  • Rafie Muhammad (finder)

Website Distribution by Country

Number of websites using CVE-2026-16230
United States346 websites



France62 websites
Germany60 websites
GB58 websites
Canada48 websites
Australia41 websites
Italy38 websites
Netherlands29 websites
Spain25 websites
Brazil21 websites

Website Distribution by TLD

Number of websites using CVE-2026-16230
.com435 websites
.org47 websites
.com.au40 websites
.co.uk37 websites
.it33 websites
.nl32 websites
.fr30 websites
.ca25 websites
.de22 websites
.com.br21 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-16230

Top websites that are affected by CVE-2026-16230. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.us United States***,***
*********.org Germany***,***
********.com United States***,***
*********.***.au United States***,***
****.cz Czech Republic***,***
*********.be Belgium***,***
*******.me United States***,***
****************.com United States***,***
*************.com United States***,***
*********.***.br Brazil***,***
See full domain list

FAQ

CVE-2026-16230 is Relative Path Traversal in Formidable Forms
A total of 931 websites have been identified as vulnerable to CVE-2026-16230, based on global website indexing conducted by WebTechSurvey.
The Formidable Forms is affected by the CVE-2026-16230 vulnerability.
Formidable Forms versions up to and including 3.0.6 are vulnerable to CVE-2026-16230.