Sceawere

Vulnerability Detail

CVE-2026-15897UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Super Forms Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
17h ago
Vendor
WebRehab
Product
Super Forms – Drag & Drop Form Builder
Attack Type
CWE-269 Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Because the super_save_form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register_login_action='update' with register_login_user_id_update='true') and then submit it with user_id set to an administrator's ID along with a new user_pass/user_email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts — including administrators — resulting in account takeover and full site compromise.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-02T06:16:41.053Z",
  "pubdate": "2026-10-02T06:16:41.053Z",
  "executiveSummary": "The Super Forms – Drag & Drop Form Builder plugin for WordPress is susceptible to a critical privilege escalation vulnerability. The flaw exists within the Register & Login add-on, allowing authenticated users with at least Subscriber-level access to hijack arbitrary accounts, including those with administrative privileges.\nThe vulnerability stems from improper input validation and the absence of authorization checks within the 'super_save_form' AJAX action and the 'before_email_success_msg()' function. By manipulating the 'register_login_action' flow, an attacker can supply a target user ID to the 'wp_update_user()' function without verifying ownership or capabilities. This leads to unauthorized modification of account credentials, such as email addresses and passwords.\nSuccessful exploitation results in full site compromise through complete account takeover. The attack requires authenticated access, but because the plugin lacks necessary capability enforcement, even low-privileged users can execute this exploit. The vulnerability affects all versions of the plugin up to and including 6.3.316. Immediate remediation is required to prevent unauthorized administrative access and potential remote code execution or data exfiltration resulting from a compromised administrator account.",
  "technicalDetails": "The vulnerability is rooted in a critical failure of authorization within the Super Forms plugin's Register & Login add-on. Specifically, the 'before_email_success_msg()' function facilitates an 'update' flow ('register_login_action=update') that processes user profile modifications. The core of the flaw lies in the function's reliance on user-supplied input for the 'user_id' parameter, which is passed directly to the WordPress core function 'wp_update_user()' without any validation of the requester's identity or permissions regarding the target account.\nThe attack surface is exposed through the 'super_save_form' AJAX action. This endpoint is globally accessible to authenticated users and fails to perform any capability checks (e.g., 'current_user_can') to ensure the user is authorized to perform form submission or profile updates. An attacker with Subscriber-level privileges can craft a malicious form configuration that includes the 'register_login_action=update' and 'register_login_user_id_update=true' parameters.\nThe attack flow proceeds as follows: 1) The attacker initiates an authenticated session on the target WordPress site. 2) The attacker utilizes the 'super_save_form' AJAX endpoint to submit a form configuration designed to trigger the 'before_email_success_msg()' update routine. 3) In the request payload, the attacker includes the 'user_id' of a target account (e.g., an administrator with ID 1) and specifies new values for 'user_pass' and 'user_email'. 4) Because the plugin logic trusts the 'user_id' provided in the request, it invokes 'wp_update_user()' to overwrite the administrator's credentials with the attacker-controlled data. 5) Once the backend process completes, the attacker gains full control over the target account, effectively bypassing all authentication barriers.\nThis vulnerability is classified as a broken access control issue, specifically improper authorization. Because 'wp_update_user()' executes with the context of the current request, it successfully modifies the database records of the specified user. The absence of strict input sanitization and verification ensures that the plugin provides a direct vector for privilege escalation. Any authenticated user can perform this action, making it a high-severity threat for all WordPress installations using versions up to 6.3.316, as it grants attackers the ability to escalate privileges from Subscriber to Administrator, ultimately leading to total site compromise and potential injection of malicious scripts or persistent backdoors."
}
CVE-2026-15897: Super Forms Privilege Escalation Vulnerability (HIGH Severity, CVSS: 8.8) | Sceawere