Privilege Escalation in Super Forms Plugin for WordPress
CVE-2026-15989
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 1 October 2026
What is CVE-2026-15989?
The Super Forms β Drag & Drop Form Builder plugin for WordPress is exposed to a privilege escalation vulnerability due to improper validation in the Register & Login add-on's before_email_success_msg() function. Specifically, it allows unauthenticated users to manipulate the 'role' key in the user-data array that interfaces with the wp_insert_user() function. This flaw permits attackers to register accounts with elevated privileges, such as the Administrator role, by simply injecting 'role=administrator' into the registration form submission. Site administrators should take immediate action to mitigate this risk by ensuring proper validation measures are in place to safeguard against unauthorized role assignments.
Affected Version(s)
Super Forms β Drag & Drop Form Builder 0 <= 6.3.316