DEV Community

jeffrey
jeffrey

Posted on

CVE-2026-15896: an unauthenticated path traversal in the Super Forms WordPress plugin

CVE-2026-15896: an unauthenticated path traversal in the Super Forms WordPress plugin

WordPress plugins are a supply chain that site owners rarely audit. CVE-2026-15896 in the Super Forms Drag & Drop Form Builder plugin is a reminder of how much a single outdated plugin can expose.

The flaw

The affected versions are up to and including 6.3.316. The parse_request function does not constrain the path it builds, so the request can escape the intended directory. An unauthenticated attacker can read arbitrary file contents from the server.
The rating is 9.1, and the default configuration is exposed: the disclosure notes that no authentication is required by default.
Path traversal in a form builder is a specific kind of problem. Form plugins process user input by design, so the request that carries the traversal looks like ordinary traffic to the plugin's own endpoints. It is not an attack against WordPress core; it is an attack against a feature that reads files as part of its normal work.

What an attacker reads first

Arbitrary file read is often described as a lower-severity finding than remote code execution, and that framing misses the practical result. The files worth reading on a WordPress host are well known.
wp-config.php holds the database credentials and the authentication salts. With the salts, an attacker can forge session cookies. A database export or a plugin's own backup file frequently contains user records. An .htaccess file or a server configuration fragment reveals what else is on the host.
The read is therefore not an end in itself. It is a step that produces credentials, and credentials are what turn a file read into a foothold.

Remediation steps

Update the plugin to a fixed version, and verify the update actually applied. Managed WordPress hosts sometimes carry an older copy in a staging layer, so the production check should be a request rather than a dashboard status.
If the site runs any version at or below 6.3.316, assume the host is potentially compromised. Search for web shells in the uploads directory, review the WordPress user list for accounts you did not create, and check the options table for unexpected entries. Those are the common persistence points after a file-read-driven compromise.
Rotate the database credentials and the WordPress salts. Because the salts live in the file the attacker could read, a session forged before the rotation may remain valid until the salts change.
The monitoring that would have caught this is worth adding. A request to a plugin endpoint that includes ../ sequences is unusual enough to block at the web application firewall, and that rule protects against future traversal bugs in the same family.

References

Top comments (0)