Harmonic Design HDForms Path Traversal Vulnerability Allowing Arbitrary File Deletion

Vulnerability

A path traversal vulnerability has been identified in the Harmonic Design HDForms WordPress plugin, specifically in versions through 1.6.1. This vulnerability allows for arbitrary file deletion, which could lead to the removal of critical files from a website, potentially causing the site to malfunction.

Impact

Exploitation of this vulnerability could result in the deletion of files from the affected WordPress site. If essential core files are removed, it could disrupt the site's functionality and cause it to break.

Remediation

Patchstack has released a mitigation rule to block attacks targeting this vulnerability. Users can activate this mitigation through Patchstack's services.

Added: Jan 22, 2026, 8:53 PM
Updated: Jan 22, 2026, 8:53 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
7.4
remediation
0.0
relevance
2.3
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.