CVE-2026-15989 is a critical (CVSS 9.8) privilege escalation flaw in the Super Forms – Drag & Drop Form Builder plugin for WordPress, in all versions up to and including 6.3.316. On sites that have a published Super Forms registration form, anyone without an account can register a new Administrator account.
What Is It
The flaw is in the plugin's Register & Login add-on. Its before_email_success_msg() function accepts a role key sent by the client and copies it into the user-data array. That array goes straight to WordPress's wp_insert_user().
The function has no safeguards on that value:
- It doesn't check the submitted role against the role the site administrator configured (register_user_role).
- It doesn't restrict roles to an allow-list.
- It doesn't run a current_user_can() capability check.
An attacker who adds role=administrator to a submission on any published Super Forms registration form (register_login_action='register') gets a new account with the Administrator role. The weakness is classified as CWE-269 (Improper Privilege Management).
Why It Matters
The CVSS 3.1 vector is AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H:
- It can be exploited over the network.
- Attack complexity is low.
- No privileges or user interaction are needed.
- Confidentiality, integrity and availability impacts are all high.
An administrator account gives full control of the WordPress site. The only condition is that the site has a published Super Forms registration form.
Exploitation status: CVE-2026-15989 is not in the CISA KEV catalog, so KEV does not currently confirm active exploitation in the wild.
What's Vulnerable
- Vendor: WebRehab
- Product: Super Forms – Drag & Drop Form Builder (WordPress plugin)
- Affected versions: all versions from 0 up to and including 6.3.316
- Affected component: Register & Login add-on, specifically sites with a published registration form
No affected CPEs are listed in the NVD record.
Patch Status
The NVD record does not name a fixed version. Its references include a GitHub pull request on the plugin's repository (RensTillmann/super-forms #205) and a Wordfence vulnerability advisory. Site owners should check both for remediation details.
Because the CVE has no KEV entry, CISA has not set a required action or due date for it.
Until a fixed release is confirmed, administrators running version 6.3.316 or earlier should: - Review whether any Super Forms registration forms are published. - Audit user accounts for unexpected Administrator accounts.
The record's NVD status is "Deferred." It was published 2026-10-01.