Privilege Escalation in Super Forms Plugin for WordPress
CVE-2026-15989

9.8CRITICAL

What is CVE-2026-15989?

The Super Forms – Drag & Drop Form Builder plugin for WordPress is exposed to a privilege escalation vulnerability due to improper validation in the Register & Login add-on's before_email_success_msg() function. Specifically, it allows unauthenticated users to manipulate the 'role' key in the user-data array that interfaces with the wp_insert_user() function. This flaw permits attackers to register accounts with elevated privileges, such as the Administrator role, by simply injecting 'role=administrator' into the registration form submission. Site administrators should take immediate action to mitigate this risk by ensuring proper validation measures are in place to safeguard against unauthorized role assignments.

Affected Version(s)

Super Forms – Drag & Drop Form Builder 0 <= 6.3.316

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

d.v4n_s3c
.