Impact
The flaw is a directory traversal in the plugin’s parse_request function that permits unauthenticated users to read any file on the server’s file system. Because the default configuration allows file uploads without authentication, the path traversal can be leveraged to exfiltrate sensitive information, thereby compromising the confidentiality of the site’s data.
Affected Systems
The vulnerability resides in the WebRehab Super Forms – Drag & Drop Form Builder plugin for WordPress and affects all releases up to and including version 6.3.316.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity, but the EPSS score is not provided, and the flaw is not listed in CISA’s KEV catalog. The exploit requires that the form has file upload enabled and, on Linux, a real 13‑digit timestamp directory already exists, while on Windows a hard-coded 13‑digit prefix suffices. Consequently, the likelihood of successful exploitation depends on the site’s specific file upload configuration and the presence of the requisite path components.
OpenCVE Enrichment