Super Forms – Drag & Drop Form Builder
Super Forms – Drag & Drop Form Builder builds WordPress forms using a drag-and-drop editor and configurable fields.
Super Forms – Drag & Drop Form Builder (super-forms-drag-drop-form-builder) is a WordPress plugin with 2 published CVE records in this archive. The latest tracked vulnerability was published Oct 01, 2026; the highest published CVSS base score is 9.8.
super-forms-drag-drop-form-builderCVE-2026-15989: Super Forms – Drag & Drop Form Builder: Privilege escalation or authentication bypass
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').
| Safe version |
|
||
|---|---|---|---|
| Oct 01, 2026 |
CVE-2026-15989
Super Forms – Drag & Drop Form Builder: Privilege escalation or authentication bypass
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').
|
See mitigation notes |
CVE9.8
NVDPending
|
| Jul 10, 2026 |
CVE-2026-14894
Super Forms – Drag & Drop Form Builder: Dangerous file upload
Super Forms – Drag & Drop Form Builder is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 6.3.313.
|
See mitigation notes |
CVE9.8
NVDPending
|