CVE-2026-15896
Received Received - Intake

Directory Traversal in Super Forms WordPress Plugin

Vulnerability report for CVE-2026-15896, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Wordfence

Description

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin's file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-26 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize "/dir/../filename" sequences that can resolve to a location that is outside of that directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Directory Traversal flaw in the Super Forms WordPress plugin up to version 6.3.316. It allows unauthenticated attackers to read arbitrary files on the server by exploiting the parse_request function. The issue stems from improper path validation, enabling access to sensitive files. Default settings do not require authentication, making exploitation easier. Enabling the 'file_upload_auth' setting mitigates unauthenticated access but does not fix the core traversal issue.

Detection Guidance

Check if the Super Forms plugin is installed and its version is up to 6.3.316. Look for unusual file access patterns or requests to the parse_request function. Examine server logs for file upload attempts with 13-digit directory names.

Impact Analysis

This vulnerability can allow attackers to read sensitive files on your server, including configuration files, user data, or system files. On Linux, attackers need a real 13-digit timestamp directory to exist, while Windows requires only a hardcoded 13-digit prefix. If file uploads are enabled, the vulnerability is exploitable regardless of authentication status. This could lead to data breaches, unauthorized access, or further compromise of the server.

Compliance Impact

This vulnerability can lead to unauthorized access to sensitive data, violating GDPR's data protection principles and HIPAA's security requirements. Exposure of personal or health information could result in regulatory fines, legal liabilities, and reputational damage. Organizations must address this flaw promptly to maintain compliance with these standards.

Mitigation Strategies

Update the Super Forms plugin to the latest version. Disable file upload functionality if not required. Enable the 'file_upload_auth' setting to require authentication for file uploads. Restrict server file access permissions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15896. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart