Description
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 6.3.316 via the upload_files function. This is due to missing file type validation in the upload_files function, which reads and applies an attacker-controlled extensions string from _super_elements post meta verbatim as the allowed MIME type map. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The attack requires a preceding step: poisoning the _super_elements post meta via the super_save_form AJAX handler, which lacks a capability and nonce check but requires the attacker to be authenticated as at minimum a Subscriber-level user; the subsequent file upload via super_upload_files requires no authentication at all.
Published: 2026-10-08
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the upload_files function of the Super Forms plugin, where the extensions string from post meta is used verbatim to build the MIME type map without validation. This permits an authenticated user with Subscriber-level privileges to upload files that may be executable. The omission of file type checks and the potential for arbitrary code execution classifies the issue under CWE-434, making it a severe security flaw.

Affected Systems

The affected product is WebRehab’s Super Forms – Drag & Drop Form Builder plugin for WordPress, with all versions up to and including 6.3.316 vulnerable.

Risk and Exploitability

The CVSS score of 8.8 indicates high severity, while the EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Attackers can first poison the _super_elements post meta through the super_save_form AJAX handler—an action that requires authentication as a Subscriber-level user but lacks a proper capability and nonce check. The subsequent upload via super_upload_files does not require authentication, giving attackers a low-effort path to upload arbitrary files. Consequently, remote code execution is achievable if the attacker can upload a malicious script and later execute it on the server.

Generated by OpenCVE AI on October 8, 2026 at 06:26 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update Super Forms to version 6.3.317 or newer, which removes the unchecked MIME type mapping.
  • If an immediate update is not possible, disable the super_save_form AJAX handler for Subscriber-level users so that the precondition for uploading arbitrary files cannot be met.
  • Configure WordPress or a security plugin to restrict uploaded file types to whitelisted MIME types (e.g., images, PDFs) and block PHP and other executable extensions.

Generated by OpenCVE AI on October 8, 2026 at 06:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 05:00:00 +0000

Type Values Removed Values Added
Description The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 6.3.316 via the upload_files function. This is due to missing file type validation in the upload_files function, which reads and applies an attacker-controlled extensions string from _super_elements post meta verbatim as the allowed MIME type map. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The attack requires a preceding step: poisoning the _super_elements post meta via the super_save_form AJAX handler, which lacks a capability and nonce check but requires the attacker to be authenticated as at minimum a Subscriber-level user; the subsequent file upload via super_upload_files requires no authentication at all.
Title Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File Upload via 'extensions' Form Element Attribute
Weaknesses CWE-434
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-08T04:28:51.005Z

Reserved: 2026-07-24T19:06:25.821Z

Link: CVE-2026-17196

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T05:17:04.657

Modified: 2026-10-08T05:17:04.657

Link: CVE-2026-17196

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T06:30:17Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type