Sceawere

Vulnerability Detail

CVE-2026-15896UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Super Forms Directory Traversal Vulnerability

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.1
Creation Date
17h ago
Vendor
WebRehab
Product
Super Forms – Drag & Drop Form Builder
Attack Type
CWE-26 Path Traversal: '/dir/../filename'
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin's file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.1",
  "pubDate": "2026-10-02T06:16:40.773Z",
  "pubdate": "2026-10-02T06:16:40.773Z",
  "executiveSummary": "The Super Forms – Drag & Drop Form Builder plugin for WordPress is susceptible to an unauthenticated Directory Traversal vulnerability.\nThis flaw, present in versions up to and including 6.3.316, enables unauthorized actors to perform arbitrary file reads on the hosting server, potentially exposing sensitive configuration data or system files.\nThe root cause lies within the parse_request function, which fails to properly sanitize user-supplied input paths.\nBy default, the 'file_upload_auth' setting is disabled, allowing unauthenticated attackers to exploit the vulnerability if file uploads are enabled for any form.\nWhile enabling 'file_upload_auth' provides a layer of defense, it does not address the underlying path traversal flaw.\nSuccessful exploitation allows attackers to bypass file access restrictions, granting them the ability to read files outside the intended web root.\nThis represents a critical risk to site confidentiality and potentially provides a foothold for further server-side compromise.",
  "technicalDetails": "The vulnerability resides in the parse_request function of the Super Forms WordPress plugin. This function fails to implement sufficient input validation or sanitization on file paths processed during the request lifecycle.\nThe attack vector leverages the plugin's file upload mechanism. Because the plugin returns the name of the created upload directory in its response, attackers can discover or predict valid directory structures needed for the traversal.\nOn Linux-based environments, exploitation is conditional upon the existence of a real 13-digit timestamp-based directory, which is generated by the plugin's file upload process. Conversely, on Windows environments, the traversal logic is less restrictive, allowing for exploitation using any hardcoded 13-digit prefix.\nThe exploitation flow proceeds as follows: First, the attacker identifies a form with file upload capabilities enabled. Second, they utilize the directory naming convention leaked by the plugin response to craft a request targeting the parse_request function. Third, by manipulating the path parameter with directory traversal sequences (e.g., ../), the attacker navigates outside the designated upload directory into the server's filesystem.\nThis vulnerability is classified as an unauthenticated attack because the default configuration of the 'file_upload_auth' setting is empty. Even when 'file_upload_auth' is enabled, the patch-level remediation is absent, as the underlying function remains inherently vulnerable to traversal, though it forces an authentication check that may limit the threat surface.\nThe technical impact of this vulnerability is the disclosure of sensitive files, such as 'wp-config.php' or other application-layer configuration files containing database credentials, API keys, and secret tokens. Because the vulnerability allows for arbitrary file reading, the attacker can systematically traverse the filesystem to identify and exfiltrate files that the web server process has read access to. This significantly elevates the risk of complete site compromise or credential theft, as the sensitive information obtained can be used to escalate privileges or gain persistent access to the server."
}
CVE-2026-15896: Super Forms Directory Traversal Vulnerability (CRITICAL Severity, CVSS: 9.1) | Sceawere