Unauthenticated Arbitrary File Download in Super Forms Plugin by WordPress
CVE-2026-28167

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
24 August 2026

What is CVE-2026-28167?

The Super Forms plugin for WordPress, specifically versions up to 6.3.315, is affected by a vulnerability that allows unauthenticated users to download arbitrary files from the server. This issue poses a significant risk as it could lead to the exposure of sensitive information stored on the server. Website administrators using affected versions are urged to update immediately to ensure their sites remain secure.

Affected Version(s)

Super Forms <= 6.3.315

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

VanTastic | Patchstack Bug Bounty Program
.