Description
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').
Published: 2026-10-01
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The Super Forms – Drag & Drop Form Builder plugin for WordPress contains a critical flaw that allows an unauthenticated attacker to manipulate the 'role' parameter submitted via a registration form and create a new user with Administrator privileges. This flaw arises because the plugin copies the client-supplied 'role' directly into the data passed to wp_insert_user(), without validating it against the site's configured default role or checking the caller's capabilities. As a result, an attacker can inject role=administrator into any published Super Forms registration form, effectively gaining full control over the WordPress installation. The vulnerability is classified as a privilege escalation weakness (CWE-269) and can lead to complete compromise of the target site.

Affected Systems

All versions of the WebRehab Super Forms – Drag & Drop Form Builder plugin up to and including 6.3.316 are affected. The flaw exists in the Register & Login add-on’s before_email_success_msg() function, which is invoked on every public registration form that uses the register_login_action='register' setting.

Risk and Exploitability

The risk is extremely high, with a CVSS score of 9.8 and no EPSS data available, indicating the vulnerability is severe but exploitation probability cannot be quantified. The vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit the flaw remotely without authentication by simply submitting the altered role value through a standard form, making the attack vector likely public-facing and straightforward. Due to the lack of current_user_can() checks, the escalation path requires no prior privileges or code execution on the server.

Generated by OpenCVE AI on October 1, 2026 at 09:38 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Super Forms to a version newer than 6.3.316 or apply the vendor-provided patch that removes unvalidated role assignment from the registration flow.
  • Disable the Register & Login add-on or configure the plugin to ignore any client-supplied role parameter when creating users.
  • Audit all public registration forms to ensure they do not forward the 'role' field to the backend and, if necessary, implement additional input validation or a web application firewall rule to block requests attempting to set the role to administrator.

Generated by OpenCVE AI on October 1, 2026 at 09:38 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Webrehab
Webrehab super Forms – Drag & Drop Form Builder
Wordpress-extensions
Wordpress-extensions super Forms
Vendors & Products Webrehab
Webrehab super Forms – Drag & Drop Form Builder
Wordpress-extensions
Wordpress-extensions super Forms

Thu, 01 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 01 Oct 2026 08:00:00 +0000

Type Values Removed Values Added
Description The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').
Title Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T13:47:45.799Z

Reserved: 2026-07-16T19:39:59.927Z

Link: CVE-2026-15989

cve-icon Vulnrichment

Updated: 2026-10-01T13:47:39.935Z

cve-icon NVD

Status : Deferred

Published: 2026-10-01T08:16:51.233

Modified: 2026-10-01T14:17:28.893

Link: CVE-2026-15989

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:36:37Z

Weaknesses
  • CWE-269

    Improper Privilege Management