CVE-2026-15896 is a critical directory traversal bug in the Super Forms – Drag & Drop Form Builder plugin for WordPress, through version 6.3.316. In the default configuration, the vulnerable code path requires no login. Whether an unauthenticated attacker can actually read arbitrary files depends on the host: on Windows the traversal works without preconditions, while on Linux it requires an existing timestamp-named directory, which is most likely obtainable when file upload is enabled on a form.
What Is It
The flaw is in the plugin's parse_request function, and it lets an attacker read the contents of arbitrary files on the server. Those files can contain sensitive information. The CNA, Wordfence, classifies the weakness as CWE-26 (Path Traversal).
The plugin's optional file_upload_auth setting is empty by default, so the default configuration requires no authentication. How the attack works depends on the host operating system:
- Linux: a real directory named with a 13-digit timestamp has to exist.
- Windows: the traversal works with any hardcoded 13-digit prefix.
On Linux, the plugin's file upload response returns the name of the directory it created. That suggests the flaw is likely exploitable on Linux whenever file upload is enabled on a form, because an attacker could get a valid directory name from the upload response.
Why It Matters
Wordfence gives the flaw a CVSS 3.1 base score of 9.1 (CRITICAL), with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H. The attack works over the network, has low complexity, and needs no privileges and no user interaction.
The vector and the description don't fully agree. The vector rates Confidentiality as None and Integrity and Availability as High, but the description says the main impact is reading arbitrary files. Defenders should go by the described impact: sensitive files on the server can be exposed.
As of this writing, the CISA Known Exploited Vulnerabilities (KEV) catalog has no entry for this CVE, so CISA has not confirmed active exploitation. NVD lists the record's status as "Deferred."
What's Vulnerable
- Vendor: WebRehab
- Product: Super Forms – Drag & Drop Form Builder (WordPress plugin)
- Affected versions: all versions up to and including 6.3.316
- Highest exposure: sites using the default configuration (
file_upload_authempty) with file upload enabled on a form
The record lists no specific CPEs.
Patch Status
The source data doesn't name a fixed release. The record links to an upstream GitHub pull request (RensTillmann/super-forms #205) and a Wordfence advisory. Administrators should check those for current patch status and update the plugin to a version newer than 6.3.316 once one is available.
Until then, turn on the file_upload_auth setting. Based on the record's description, this should block unauthenticated exploitation, but the record states it does not fix the path traversal itself. Also review which forms have file upload enabled. Because the CVE is not in KEV, CISA has not issued a required action.