CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-15989 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...

·Source: NIST NVD

Updated:

Executive Summary

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role ag

Analysis

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register'). CVSS Score: 9.8. Published: 2026-10-01T08:16:51.233.

Indicators of Compromise (1)

CVE (1)
CVE-2026-15989
Source Attribution

Originally published by NIST NVD on Oct 1, 2026. Verified by: NIST.

Related Threats