{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/super-forms--drag--drop-form-builder--6.3.316/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:super_forms:super_forms:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.1,"id":"CVE-2026-17609"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Super Forms – Drag \u0026 Drop Form Builder (\u003c= 6.3.316)"],"_cs_severities":["high"],"_cs_tags":["wordpress","vulnerability","remote-deletion","web-application"],"_cs_type":"advisory","_cs_vendors":["Super Forms"],"content_html":"\u003cp\u003eThe Super Forms - Drag \u0026amp; Drop Form Builder plugin for WordPress (versions \u0026lt;= 6.3.316) is vulnerable to an arbitrary directory deletion vulnerability. The flaw exists within the submit_form function, where insufficient validation of JSON field declarations allows for path manipulation. Attackers can bypass the ABSPATH security guard by using the dirname() function to strip trailing slashes, effectively traversing the filesystem. If an administrator has enabled the 'Delete files from server after form submissions' setting, an unauthenticated attacker can recursively delete arbitrary directories, including the entire WordPress installation. This vulnerability poses a severe risk to service availability and data integrity for any WordPress site utilizing this plugin with the specific administrative setting enabled.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress installation running a vulnerable version of the Super Forms plugin (\u0026lt;= 6.3.316).\u003c/li\u003e\n\u003cli\u003eAttacker verifies the plugin's 'Delete files from server after form submissions' setting is active, commonly found in plugin configurations.\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious JSON payload targeting the submit_form function.\u003c/li\u003e\n\u003cli\u003eAttacker includes a directory path string designed to bypass the ABSPATH security guard via dirname() behavior.\u003c/li\u003e\n\u003cli\u003eAttacker sends an HTTP POST request to the plugin's submission endpoint containing the crafted JSON.\u003c/li\u003e\n\u003cli\u003eThe application parses the malicious JSON and fails to validate the directory path against the intended schema.\u003c/li\u003e\n\u003cli\u003eThe application executes the recursive deletion command on the provided target path.\u003c/li\u003e\n\u003cli\u003eFinal objective is achieved as the target directory (e.g., WordPress root) is deleted from the server.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in the recursive deletion of arbitrary directories on the host server. If the WordPress root directory is targeted, it results in complete application destruction and permanent data loss for the affected site. As the plugin is a popular form builder, numerous WordPress deployments globally are potentially at risk.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately upgrade the Super Forms plugin to the latest available patched version.\u003c/li\u003e\n\u003cli\u003eDisable the 'Delete files from server after form submissions' feature in the Super Forms configuration if an immediate update is not possible.\u003c/li\u003e\n\u003cli\u003eAudit existing form submissions and plugin logs for any unexpected HTTP POST requests directed at the submit_form endpoint that contain directory traversal patterns (e.g., '../').\u003c/li\u003e\n\u003cli\u003eEnsure regular off-site backups are maintained to recover from potential data destruction events.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-08T06:50:18Z","date_published":"2026-10-08T06:50:18Z","id":"https://feed.craftedsignal.io/briefs/2026-10-super-forms-rce/","summary":"Unauthenticated attackers can achieve arbitrary recursive directory deletion in Super Forms versions 6.3.316 and earlier by exploiting improper path validation in the submit_form function.","title":"Arbitrary Directory Deletion in Super Forms WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-super-forms-rce/"},{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wordpress:super_forms_drag_drop_form_builder:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-15989"}],"_cs_exploited":false,"_cs_has_poc":true,"_cs_poc_references":["https://sploitus.com/exploit?id=9F5189C5-CE21-56B0-BC4D-0E6C71AE4BEA\u0026utm_source=rss\u0026utm_medium=rss"],"_cs_products":["Super Forms – Drag \u0026 Drop Form Builder (\u003c= 6.3.316)"],"_cs_severities":["critical"],"_cs_tags":["web-application","wordpress","privilege-escalation","cve-2026-15989"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Super Forms - Drag \u0026amp; Drop Form Builder plugin for WordPress is affected by a critical privilege escalation vulnerability (CVE-2026-15989) in all versions up to and including 6.3.316. The flaw exists within the Register \u0026amp; Login add-on, specifically inside the before_email_success_msg() function. This function improperly handles client-submitted data by whitelisting the 'role' key and passing it directly into the user-data array processed by wp_insert_user().\u003c/p\u003e\n\u003cp\u003eBecause the input is not validated against administrative settings, lacks an allow-list, and performs no capability checks via current_user_can(), unauthenticated attackers can inject the parameter 'role=administrator' into any public Super Forms registration form. This allows the creation of unauthorized accounts with full administrative privileges, granting the attacker complete control over the compromised WordPress instance. Defenders should identify all WordPress installations using Super Forms and ensure they are upgraded to a version beyond 6.3.316 or disable the Register \u0026amp; Login add-on immediately.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target WordPress site utilizing the Super Forms - Drag \u0026amp; Drop Form Builder plugin.\u003c/li\u003e\n\u003cli\u003eAttacker locates a public-facing registration form created with the Super Forms plugin.\u003c/li\u003e\n\u003cli\u003eAttacker initiates an HTTP POST request to the form handler, specifying register_login_action='register'.\u003c/li\u003e\n\u003cli\u003eAttacker injects the 'role=administrator' parameter into the registration form submission data.\u003c/li\u003e\n\u003cli\u003eThe server-side before_email_success_msg() function in the Register \u0026amp; Login add-on accepts the malicious 'role' key without validation.\u003c/li\u003e\n\u003cli\u003eThe system executes wp_insert_user() using the attacker-supplied role data.\u003c/li\u003e\n\u003cli\u003eA new user account is created with Administrator privileges.\u003c/li\u003e\n\u003cli\u003eAttacker authenticates with the newly created account to establish persistent administrative access.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to gain full administrative access to affected WordPress installations. This leads to complete site compromise, including the ability to execute arbitrary code (via theme or plugin file uploads), exfiltrate sensitive user data, install backdoors, or redirect site traffic. This vulnerability carries a CVSS v3.1 base score of 9.8.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpdate the Super Forms - Drag \u0026amp; Drop Form Builder plugin to a version higher than 6.3.316 immediately.\u003c/li\u003e\n\u003cli\u003eIf an update is unavailable, disable the Register \u0026amp; Login add-on to prevent exploitation of CVE-2026-15989.\u003c/li\u003e\n\u003cli\u003eAudit the user database for accounts with administrative privileges created unexpectedly after the publication of this advisory (October 1, 2026).\u003c/li\u003e\n\u003cli\u003eDeploy the provided webserver detection rule to monitor for suspicious registration attempts containing unexpected role parameters.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-10-03T00:54:01Z","date_published":"2026-10-01T08:39:24Z","id":"https://feed.craftedsignal.io/briefs/2026-10-super-forms-priv-esc/","summary":"An unauthenticated privilege escalation vulnerability (CVE-2026-15989) in the Super Forms WordPress plugin allows attackers to register administrative accounts via registration form injection.","title":"Unauthenticated Privilege Escalation in Super Forms WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-10-super-forms-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - Super Forms – Drag \u0026 Drop Form Builder (\u003c= 6.3.316)","version":"https://jsonfeed.org/version/1.1"}