Analysis and contextual insights are available on OpenCVE Cloud.
No solution or workaround provided in the CVE record.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 08 Oct 2026 05:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Unrestricted File Type Upload in all versions up to, and including, 6.3.316 via the upload_files function. This is due to missing file type validation in the upload_files function, which reads and applies an attacker-controlled extensions string from _super_elements post meta verbatim as the allowed MIME type map. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload files that may be executable, which makes remote code execution possible. The attack requires a preceding step: poisoning the _super_elements post meta via the super_save_form AJAX handler, which lacks a capability and nonce check but requires the attacker to be authenticated as at minimum a Subscriber-level user; the subsequent file upload via super_upload_files requires no authentication at all. | |
| Title | Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File Upload via 'extensions' Form Element Attribute | |
| Weaknesses | CWE-434 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-10-08T04:28:51.005Z
Reserved: 2026-07-24T19:06:25.821Z
Link: CVE-2026-17196
No data.
Status : Received
Published: 2026-10-08T05:17:04.657
Modified: 2026-10-08T05:17:04.657
Link: CVE-2026-17196
No data.
OpenCVE Enrichment
Updated: 2026-10-08T06:30:17Z
-
CWE-434
Unrestricted Upload of File with Dangerous Type