Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-17196— Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File Upload via 'extensions' Form Element Attribute

Quick assessment

Affected
WebRehab Super Forms – Drag & Drop Form Builder
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress 插件 Super Forms – Drag & Drop Form Builder 在所有不高于 6.3.316 的版本中,存在不受限制的文件类型上传漏洞,该漏洞位于 upload_files 函数中。 漏洞根源在于 upload_files 函数缺少对文件类型的验证,它会原样读取并应用攻击者控制的 文章元数据(post meta)中的扩展名字符串,将其用作允许的 MIME 类型映射。这使得具有订阅者(Subscriber)级及以上权限的认证攻击者能够上传可执行文件,从而可能导致远程代码执行(R

CVSS 8.8 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-17196

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File Upload via 'extensions' Form Element Attribute
Source: CVE Program / CVE List V5
Vulnerability Description
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 6.3.316 via the upload_files function. This is due to missing file type validation in the upload_files function, which reads and applies an attacker-controlled extensions string from _super_elements post meta verbatim as the allowed MIME type map. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The attack requires a preceding step: poisoning the _super_elements post meta via the super_save_form AJAX handler, which lacks a capability and nonce check but requires the attacker to be authenticated as at minimum a Subscriber-level user; the subsequent file upload via super_upload_files requires no authentication at all.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
危险类型文件的不加限制上传
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
WebRehab Super Forms – Drag & Drop Form Builder 0 ~ 6.3.316 -

II. Public POCs for CVE-2026-17196

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-17196

请登录查看更多情报信息。

Other References for CVE-2026-17196 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-17196

No comments yet


Leave a comment