CVE-2026-15896: Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter

Published Oct 2, 2026
·
Updated

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parserequest function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'fileuploadauth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin's file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form.

Affected Software

1 affected component
Super Forms Super Forms – Drag & Drop Form Builder<=6.3.316

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Enable the optional file_upload_auth setting to require authentication for file uploads; this mitigates unauthenticated exploitation but does not remediate the path traversal.

    Super Forms – Drag & Drop Form Builder file_upload_auth = enabled

Event History

Oct 2, 2026
CVE Published
via MITRE·05:30 AM
Data Sourced
via MITRE·05:30 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are most exposed to unauthenticated exploitation?

Forms with file upload enabled are exposed because the upload response discloses the name of the created directory needed for traversal. The optional file_upload_auth setting is empty by default, so the default configuration does not require authentication.

2

What does an attacker need to exploit this on Linux versus Windows?

On Linux, exploitation requires an existing directory named with a real 13-digit timestamp. On Windows, any hardcoded 13-digit prefix can be used; when file upload is enabled, the upload response provides the created directory name.

3

What can be done if updating is not immediately possible?

Enable the file_upload_auth setting to mitigate unauthenticated exploitation. This does not fix the underlying path traversal vulnerability, so it should be treated as a temporary mitigation.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203