CVE-2026-15896: Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parserequest function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'fileuploadauth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin's file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable the optional file_upload_auth setting to require authentication for file uploads; this mitigates unauthenticated exploitation but does not remediate the path traversal.
Super Forms – Drag & Drop Form Builder file_upload_auth = enabled
Event History
Frequently Asked Questions
Which deployments are most exposed to unauthenticated exploitation?
Forms with file upload enabled are exposed because the upload response discloses the name of the created directory needed for traversal. The optional file_upload_auth setting is empty by default, so the default configuration does not require authentication.
What does an attacker need to exploit this on Linux versus Windows?
On Linux, exploitation requires an existing directory named with a real 13-digit timestamp. On Windows, any hardcoded 13-digit prefix can be used; when file upload is enabled, the upload response provides the created directory name.
What can be done if updating is not immediately possible?
Enable the file_upload_auth setting to mitigate unauthenticated exploitation. This does not fix the underlying path traversal vulnerability, so it should be treated as a temporary mitigation.