Super Forms
by WordPress
CVEs (3)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-15989 | Cri | 0.57 | 9.8 | — | Oct 1, 2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key… | ||
| CVE-2026-28167 | Hig | 0.49 | 7.5 | 0.01 | Aug 24, 2026 | Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions. | ||
| CVE-2026-14894 | Cri | 0.00 | 9.8 | 0.05 | Jul 10, 2026 | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the… |
- risk 0.57cvss 9.8epss —
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key…
- risk 0.49cvss 7.5epss 0.01
Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.
- risk 0.00cvss 9.8epss 0.05
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the…