Impact
The Super Forms – Drag & Drop Form Builder plugin in WordPress allows an authenticated user with Subscriber level access to crash an account takeover vector by sending a specially crafted AJAX request. The Register & Login add‑on accepts a user_id parameter without ownership checks, then passes it to wp_update_user(), enabling overwrite of any user's credentials including administrators. This results in full control of the compromised accounts and the entire site.
Affected Systems
The vulnerability covers all versions of the WebRehab Super Forms – Drag & Drop Form Builder plugin for WordPress up to and including 6.3.316.
Risk and Exploitability
With a CVSS score of 8.8 the flaw is considered High. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Attackers only need an authenticated account with Subscriber privilege and can achieve the exploit by creating a malicious form and submitting it through the super_save_form AJAX endpoint. The lack of capability checks in that action makes the exploit straightforward for a legitimate user, creating a significant risk of credential hijacking and site compromise.
OpenCVE Enrichment