Cyber & AI intelligence
Wasteland.
Briefs indexed2957
Issues30
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-15989 2026-10-01

Super Forms WordPress Plugin Flaw Lets Unauthenticated Attackers Register as Administrator (CVE-2026-15989)

"CVE-2026-15989 is a critical (CVSS 9.8) privilege escalation flaw in the Super Forms – Drag & Drop Form Builder plugin for WordPress, in all versions up to and including 6.3.316. On sites that have a published Super…"

CVE-2026-15989 is a critical (CVSS 9.8) privilege escalation flaw in the Super Forms – Drag & Drop Form Builder plugin for WordPress, in all versions up to and including 6.3.316. On sites that have a published Super Forms registration form, anyone without an account can register a new Administrator account.

What Is It

The flaw is in the plugin's Register & Login add-on. Its before_email_success_msg() function accepts a role key sent by the client and copies it into the user-data array. That array goes straight to WordPress's wp_insert_user().

The function has no safeguards on that value: - It doesn't check the submitted role against the role the site administrator configured (register_user_role). - It doesn't restrict roles to an allow-list. - It doesn't run a current_user_can() capability check.

An attacker who adds role=administrator to a submission on any published Super Forms registration form (register_login_action='register') gets a new account with the Administrator role. The weakness is classified as CWE-269 (Improper Privilege Management).

Why It Matters

The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H: - It can be exploited over the network. - Attack complexity is low. - No privileges or user interaction are needed. - Confidentiality, integrity and availability impacts are all high.

An administrator account gives full control of the WordPress site. The only condition is that the site has a published Super Forms registration form.

Exploitation status: CVE-2026-15989 is not in the CISA KEV catalog, so KEV does not currently confirm active exploitation in the wild.

What's Vulnerable

No affected CPEs are listed in the NVD record.

Patch Status

The NVD record does not name a fixed version. Its references include a GitHub pull request on the plugin's repository (RensTillmann/super-forms #205) and a Wordfence vulnerability advisory. Site owners should check both for remediation details.

Because the CVE has no KEV entry, CISA has not set a required action or due date for it.

Until a fixed release is confirmed, administrators running version 6.3.316 or earlier should: - Review whether any Super Forms registration forms are published. - Audit user accounts for unexpected Administrator accounts.

The record's NVD status is "Deferred." It was published 2026-10-01.

Sources