---
id: CVE-2026-15989
title: >-
  The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable
  to Privilege Escalation in all versions up to, and including, 6.3.316
summary: >-
  The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable
  to Privilege Escalation in all versions up to, and including, 6.3.316. This is
  due to the Register & Login add-on's before_email_success_msg() function
  whiteli…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: WebRehab
product: Super Forms – Drag & Drop Form Builder
affected:
  - super_forms_drag_drop_form_builder <= 6.3.316
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T08:16:51.233'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15989'
references:
  - url: 'https://github.com/RensTillmann/super-forms/pull/205'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/7eb62d35-3f0e-4733-8f7f-723d0f25b710?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T08:40:11.739Z'
---

## Overview

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
