VYPR

Super Forms

by WordPress

CVEs (3)

  • CVE-2026-15989CriOct 1, 2026
    risk 0.57cvss 9.8epss —

    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key…

  • CVE-2026-28167HigAug 24, 2026
    risk 0.49cvss 7.5epss 0.01

    Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.

  • CVE-2026-14894CriJul 10, 2026
    risk 0.00cvss 9.8epss 0.05

    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the…