← WordPress Vulnerabilities
WordPress security by component

Super Forms – Drag & Drop Form Builder

Super Forms – Drag & Drop Form Builder builds WordPress forms using a drag-and-drop editor and configurable fields.

Super Forms – Drag & Drop Form Builder (super-forms-drag-drop-form-builder) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Oct 01, 2026; the highest published CVSS base score is 9.8.

Plugin slug: super-forms-drag-drop-form-builder

CVE-2026-15989: Super Forms – Drag & Drop Form Builder: Privilege escalation or authentication bypass

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').

PublishedOct 01, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for super-forms-drag-drop-form-builder
Safe version
Oct 01, 2026 CVE-2026-15989
Super Forms – Drag & Drop Form Builder: Privilege escalation or authentication bypass
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').
See mitigation notes
CVE9.8
NVDPending
Jul 10, 2026 CVE-2026-14894
Super Forms – Drag & Drop Form Builder: Dangerous file upload
Super Forms – Drag & Drop Form Builder is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 6.3.313.
See mitigation notes
CVE9.8
NVDPending