NVD CRITICAL: CVE-2026-15989 — The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to...
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role ag
CVE-2026-15989