Impact
The Super Forms – Drag & Drop Form Builder plugin for WordPress contains a critical flaw that allows an unauthenticated attacker to manipulate the 'role' parameter submitted via a registration form and create a new user with Administrator privileges. This flaw arises because the plugin copies the client-supplied 'role' directly into the data passed to wp_insert_user(), without validating it against the site's configured default role or checking the caller's capabilities. As a result, an attacker can inject role=administrator into any published Super Forms registration form, effectively gaining full control over the WordPress installation. The vulnerability is classified as a privilege escalation weakness (CWE-269) and can lead to complete compromise of the target site.
Affected Systems
All versions of the WebRehab Super Forms – Drag & Drop Form Builder plugin up to and including 6.3.316 are affected. The flaw exists in the Register & Login add-on’s before_email_success_msg() function, which is invoked on every public registration form that uses the register_login_action='register' setting.
Risk and Exploitability
The risk is extremely high, with a CVSS score of 9.8 and no EPSS data available, indicating the vulnerability is severe but exploitation probability cannot be quantified. The vulnerability is not yet listed in the CISA KEV catalog. Attackers can exploit the flaw remotely without authentication by simply submitting the altered role value through a standard form, making the attack vector likely public-facing and straightforward. Due to the lack of current_user_can() checks, the escalation path requires no prior privileges or code execution on the server.
OpenCVE Enrichment