CRITICAL
9.1 CVE-2026-15896 Published 2 Oct 2026
Super Forms WordPress Plugin Directory Traversal Vulnerability
Worried this affects your website?
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function.
This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information.
- Affected versions: all versions up to, and including, 6.3.316.
- The optional file_upload_auth setting defaults to empty, so no authentication is required in the default configuration; enabling it mitigates unauthenticated exploitation but does not remediate the path traversal itself.
- On Linux, exploitation requires a real 13-digit timestamp directory to exist; on Windows, the traversal works with any hardcoded 13-digit prefix.
- The plugin's file upload response returns the name of the created directory, so the vulnerability is exploitable as long as file upload is enabled on the form.
Reference: CVE-2026-15896 on NVD
← Back to Security News