---
id: CVE-2026-17196
title: >-
  The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable
  to Unrestricted File Type Upload in all versions up to, and including, 6.3.316
  via the upload_files function
summary: >-
  The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable
  to Unrestricted File Type Upload in all versions up to, and including, 6.3.316
  via the upload_files function. This is due to missing file type validation in
  th…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-434
vendor: WebRehab
product: Super Forms – Drag & Drop Form Builder
affected:
  - super_forms_drag_drop_form_builder <= 6.3.316
published: '2026-10-08'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T18:17:28.443'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-17196'
references:
  - url: 'https://github.com/RensTillmann/super-forms/pull/205'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/63db136b-58da-4758-a506-4dc79b3c177d?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-10-08T17:54:24.458370Z'
ingestedAt: '2026-10-08T05:05:36.677Z'
---

## Overview

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 6.3.316 via the upload_files function. This is due to missing file type validation in the upload_files function, which reads and applies an attacker-controlled extensions string from _super_elements post meta verbatim as the allowed MIME type map. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The attack requires a preceding step: poisoning the _super_elements post meta via the super_save_form AJAX handler, which lacks a capability and nonce check but requires the attacker to be authenticated as at minimum a Subscriber-level user; the subsequent file upload via super_upload_files requires no authentication at all.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
