Unrestricted File Type Upload Vulnerability in Super Forms Plugin for WordPress
CVE-2026-17196

8.8HIGH

What is CVE-2026-17196?

The Super Forms – Drag & Drop Form Builder plugin for WordPress is susceptible to an Unrestricted File Type Upload issue in all versions up to and including 6.3.316. This vulnerability stems from inadequate file type validation within the upload_files function, which allows attackers with Subscriber-level access or higher to upload potentially executable files. The exploitation sequence requires an authenticated attacker to manipulate the _super_elements post meta via the super_save_form AJAX handler, which inadequately checks capabilities and nonce values. Following this, the super_upload_files endpoint can be called without any authentication, enabling the upload of harmful files that may lead to remote code execution.

Affected Version(s)

Super Forms – Drag & Drop Form Builder 0 <= 6.3.316

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

d.v4n_s3c
.