Unrestricted File Type Upload Vulnerability in Super Forms Plugin for WordPress
CVE-2026-17196
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 8 October 2026
What is CVE-2026-17196?
The Super Forms β Drag & Drop Form Builder plugin for WordPress is susceptible to an Unrestricted File Type Upload issue in all versions up to and including 6.3.316. This vulnerability stems from inadequate file type validation within the upload_files function, which allows attackers with Subscriber-level access or higher to upload potentially executable files. The exploitation sequence requires an authenticated attacker to manipulate the _super_elements post meta via the super_save_form AJAX handler, which inadequately checks capabilities and nonce values. Following this, the super_upload_files endpoint can be called without any authentication, enabling the upload of harmful files that may lead to remote code execution.
Affected Version(s)
Super Forms β Drag & Drop Form Builder 0 <= 6.3.316