CVE-2026-15989
Received Received - Intake

Privilege Escalation in Super Forms WordPress Plugin

Vulnerability report for CVE-2026-15989, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Wordfence

Description

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Currently, no data is known.

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a privilege escalation flaw in the Super Forms WordPress plugin up to version 6.3.316. It allows unauthenticated attackers to register new user accounts with the Administrator role by exploiting a lack of validation in the 'role' parameter. The plugin's Register & Login add-on copies the submitted 'role' value directly into user data without checking against configured roles or requiring proper permissions.

Detection Guidance

Check WordPress sites using the Super Forms plugin for unauthorized admin accounts by reviewing user roles in the WordPress dashboard or via database query: SELECT user_login, display_name FROM wp_users WHERE meta_key = 'wp_capabilities' AND meta_value LIKE '%administrator%'; Look for unexpected accounts with admin privileges.

Impact Analysis

An attacker could exploit this to gain full administrative control of a WordPress site using the vulnerable plugin. This could lead to complete site takeover, installation of malicious plugins, theft of sensitive data, or defacement. The high CVSS score (9.8) indicates severe impact potential.

Compliance Impact

This vulnerability could lead to unauthorized administrative access, potentially violating data protection requirements under GDPR and HIPAA. Unauthorized access may result in data breaches, improper data handling, or failure to maintain proper access controls, all of which could lead to compliance violations.

Mitigation Strategies

Update the Super Forms plugin to the latest version beyond 6.3.316 to address the privilege escalation vulnerability. Disable the Register & Login add-on if not required. Review user roles and remove any unauthorized Administrator accounts created via the vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15989. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart