PT-2026-104078 · Webrehab · The Super Forms - Drag & Drop Form Builder

·

CVE-2026-15897

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before email success msg() function, in its register login action='update' flow, trusting an attacker-supplied user id value and passing it to wp update user() without any ownership or capability check. Because the super save form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register login action='update' with register login user id update='true') and then submit it with user id set to an administrator's ID along with a new user pass/user email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts — including administrators — resulting in account takeover and full site compromise.

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-15897

Affected Products

The Super Forms - Drag & Drop Form Builder