PT-2026-103714 · WordPress · Super Forms

·

CVE-2026-15989

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Super Forms – Drag & Drop Form Builder versions prior to 6.3.317
Description An issue exists in the Register & Login add-on where the before email success msg() function whitelists the client-submitted role key and copies it into the user-data array passed to wp insert user(). The process fails to validate the submitted role against the administrator-configured register user role, lacks an allow-list, and does not perform a current user can() capability check. This allows unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published registration form using the register login action='register' action.
Recommendations Update Super Forms – Drag & Drop Form Builder to version 6.3.317 or later.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15989

Affected Products

Super Forms