Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-15989— Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter

Quick assessment

Affected
WebRehab Super Forms – Drag & Drop Form Builder
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 的 Super Forms – Drag & Drop Form Builder 插件在所有版本(包括 6.3.316 及之前)中存在权限提升漏洞。该漏洞源于 Register & Login 附加组件中的 函数:该函数将客户端提交的 键加入白名单,并将其直接复制到传递给 的用户数据数组中,但未对提交的 role 值进行以下任何验证: 未与管理员配置的 进行比对; 未使用允许列表(allow-list)机制; 未执行 权限检查。 因此,未经身份验证的攻击者可以通过向任何已发布的 Super Fo

CVSS 9.8 · Critical

Possible ATT&CK Techniques 1 AI

T1098 · Account Manipulation
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-15989

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WebRehab Super Forms – Drag & Drop Form Builder 0 ~ 6.3.316 -

II. Public POCs for CVE-2026-15989

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-15989

请登录查看更多情报信息。

Security Blog Posts for CVE-2026-15989 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-15989

No comments yet


Leave a comment