Sceawere
Vulnerability Detail
CVE-2026-17196UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Super Forms Unrestricted File Upload
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 8.8
- Creation Date
- 4h ago
- Vendor
- WebRehab
- Product
- Super Forms – Drag & Drop Form Builder
- Attack Type
- CWE-434 Unrestricted Upload of File with Dangerous Type
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 6.3.316 via the upload_files function. This is due to missing file type validation in the upload_files function, which reads and applies an attacker-controlled extensions string from _super_elements post meta verbatim as the allowed MIME type map. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The attack requires a preceding step: poisoning the _super_elements post meta via the super_save_form AJAX handler, which lacks a capability and nonce check but requires the attacker to be authenticated as at minimum a Subscriber-level user; the subsequent file upload via super_upload_files requires no authentication at all.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "8.8",
"pubDate": "2026-10-08T05:17:04.657Z",
"pubdate": "2026-10-08T05:17:04.657Z",
"executiveSummary": "The Super Forms – Drag & Drop Form Builder plugin for WordPress contains a critical Unrestricted File Type Upload vulnerability affecting versions up to and including 6.3.316.\nThe vulnerability originates from the upload_files function, which fails to perform server-side validation on file extensions, allowing an attacker to manipulate the allowed MIME type map via the _super_elements post meta.\nThe impact of this flaw is severe, as it permits authenticated attackers (Subscriber-level and above) to achieve Remote Code Execution (RCE) by uploading arbitrary executable scripts to the web server.\nExploitation involves a two-stage process: an initial state-changing request to poison the plugin configuration via the super_save_form AJAX handler, followed by an unauthenticated file upload via the super_upload_files endpoint.\nGiven the ability to execute arbitrary code within the WordPress environment, this vulnerability presents a critical risk to the confidentiality, integrity, and availability of the host system, necessitating immediate attention.",
"technicalDetails": "The vulnerability is rooted in the improper implementation of file upload handling within the upload_files function of the Super Forms plugin. The function insecurely parses an attacker-controlled extensions string derived from the _super_elements post meta. Instead of enforcing a strict allow-list of safe MIME types, the application treats this user-supplied input as the authoritative configuration for permissible file types.\nThe attack vector utilizes a two-step sequence. First, the attacker must interact with the super_save_form AJAX handler. This specific endpoint lacks adequate security controls, specifically missing both capability checks and nonces. By crafting a request to this endpoint, an attacker can modify the _super_elements post meta, effectively updating the plugin's configuration to allow the upload of dangerous file extensions such as .php, .phtml, or other server-side executable scripts.\nFollowing the successful poisoning of the configuration, the attacker proceeds to the second stage: the exploitation of the super_upload_files function. Unlike the initial configuration step, this endpoint requires no authentication. By submitting a specially crafted HTTP request to this handler, the attacker can upload the malicious executable files previously enabled in the configuration phase. Because the plugin performs no server-side validation against the actual file contents or extension, the server writes these files to the filesystem.\nUpon successful upload, the attacker can access the uploaded scripts directly via their URI. This results in the execution of arbitrary code within the context of the web server process. The privilege level for the initial configuration change is limited to Subscriber-level or higher, but the final stage of file upload is entirely unauthenticated, facilitating a significant security breach. The persistent nature of the modified _super_elements metadata allows the attacker to maintain the ability to upload malicious files until the configuration is reverted or the plugin is updated.\nAffected versions include all iterations of the Super Forms – Drag & Drop Form Builder plugin up to and including 6.3.316. The vulnerability highlights a failure in input sanitization and authorization, where the plugin trusts user-supplied meta data for critical security decision-making processes."
}