CVE-2026-15897
Received Received - Intake

Privilege Escalation in Super Forms WordPress Plugin

Vulnerability report for CVE-2026-15897, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: Wordfence

Description

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Because the super_save_form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register_login_action='update' with register_login_user_id_update='true') and then submit it with user_id set to an administrator's ID along with a new user_pass/user_email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts β€” including administrators β€” resulting in account takeover and full site compromise.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
super_forms drag_and_drop_form_builder to 6.3.316 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a privilege escalation flaw in the Super Forms WordPress plugin up to version 6.3.316. It allows authenticated users with Subscriber-level access or higher to exploit a function that updates user credentials without proper checks. Attackers can create a malicious form and submit it to overwrite passwords or emails of any user, including administrators, leading to account takeover and full site compromise.

Detection Guidance

Check WordPress sites using the Super Forms plugin for versions up to 6.3.316. Look for unauthorized user credential changes or admin account modifications in logs. Inspect AJAX requests with register_login_action=update and register_login_user_id_update=true parameters.

Impact Analysis

If exploited, this vulnerability allows attackers to take over any user account on your WordPress site, including admin accounts. This could lead to full site compromise, data theft, unauthorized changes, or malware distribution. Even users with minimal access (Subscribers) can exploit it to gain control of higher-privilege accounts.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating GDPR and HIPAA requirements for data protection and access controls. A successful exploit may result in non-compliance, legal penalties, and reputational damage due to compromised sensitive user data.

Mitigation Strategies

Update the Super Forms plugin to the latest version. Remove Subscriber-level access for untrusted users. Monitor user accounts for unauthorized changes. Disable the Register & Login add-on if not needed.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15897. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart