Impact
The vulnerability resides in the upload_files function of the Super Forms plugin, where the extensions string from post meta is used verbatim to build the MIME type map without validation. This permits an authenticated user with Subscriber-level privileges to upload files that may be executable. The omission of file type checks and the potential for arbitrary code execution classifies the issue under CWE-434, making it a severe security flaw.
Affected Systems
The affected product is WebRehab’s Super Forms – Drag & Drop Form Builder plugin for WordPress, with all versions up to and including 6.3.316 vulnerable.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers can first poison the _super_elements post meta through the super_save_form AJAX handler—an action that requires authentication as a Subscriber-level user but lacks a proper capability and nonce check. The subsequent upload via super_upload_files does not require authentication, giving attackers a low-effort path to upload arbitrary files. Consequently, remote code execution is achievable if the attacker can upload a malicious script and later execute it on the server.
OpenCVE Enrichment