← Back to CVE List
Vulnerability Intelligence Report
Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter

CVE-2026-15989

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').

Privilege Escalation No Active Exploit Signals
CVSS Base Score
9.8
CRITICAL
Exploitability:3.9
Impact Score:5.9
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—

Weaknesses (CWE)

CWE-269 ↗CWE-269 Improper Privilege Management

Affected Products & Versions

Vendor Product Affected Versions
WebRehab Super Forms – Drag & Drop Form Builder 0 <= 6.3.316 (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

Vulnerability Class
Privilege Escalation

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityWordfence · Vendor · USA
Reserved2026-07-16T19:39:59
Published2026-10-01T07:40:23
Last Updated2026-10-01T13:47:45

LINK COPIED TO CLIPBOARD