Where
-Infinity
0

Vendor Risk Score

See how super forms compares to other vendors in security performance

View Risk Score →
Severity
9.1
Path Traversal
AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parserequest function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'fileuploadauth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin's file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form.

First published (updated )
Severity
8.8
AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's beforeemailsuccessmsg() function, in its registerloginaction='update' flow, trusting an attacker-supplied userid value and passing it to wpupdateuser() without any ownership or capability check. Because the supersaveform AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (registerloginaction='update' with registerloginuseridupdate='true') and then submit it with userid set to an administrator's ID along with a new userpass/useremail. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts — including administrators — resulting in account takeover and full site compromise.

First published (updated )
Severity
9.8
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's beforeemailsuccessmsg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wpinsertuser(), without validating the submitted role against the administrator-configured registeruserrole, without an allow-list, and without any currentusercan() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (registerloginaction='register').

First published (updated )
Severity
8.1
AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the supersaveform AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super Forms and enable the fileuploadsubmissiondelete setting — combined with the supersubmitform handler's submitform function passing the attacker-controlled files[].subdir value from $POST['data'] directly into SUPERCommon::deletedir() without sanitization, and a trivially bypassed ABSPATH guard that a subdir value of wp-config.php defeats because dirname(realpath(ABSPATH . $subdir)) resolves to the WordPress root while the naive ABSPATH !== $dir string check fails to match due to a trailing-slash mismatch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recursively delete arbitrary files and directories on the server, up to and including the entire WordPress installation, resulting in full site takedown and potential remote code execution if critical files such as wp-config.php are removed and the site is subsequently re-installed by another party.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203