CVE-2026-15989: Webrehab Super Forms – Drag & Drop Form Builder

Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').

Affected products

  • Webrehab Super Forms – Drag & Drop Form Builder: up to and including 6.3.316

Published 2026-10-01. Last modified 2026-10-01.