PT-2026-104078 · Webrehab · The Super Forms - Drag & Drop Form Builder
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before email success msg() function, in its register login action='update' flow, trusting an attacker-supplied user id value and passing it to wp update user() without any ownership or capability check. Because the super save form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register login action='update' with register login user id update='true') and then submit it with user id set to an administrator's ID along with a new user pass/user email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts — including administrators — resulting in account takeover and full site compromise.
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
The Super Forms - Drag & Drop Form Builder