CRITICAL 9.8 CVE-2026-15989 Published 1 Oct 2026

Super Forms WordPress Plugin Privilege Escalation Vulnerability

Worried this affects your website?

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316.

This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check.

This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').

Reference: CVE-2026-15989 on NVD

← Back to Security News