Executive Summary
A critical unauthenticated directory traversal vulnerability (CVE-2026-15896) has been disclosed in the Super Forms – Drag & Drop Form Builder plugin for WordPress, developed by WebRehab. The flaw carries a CVSS score of 9.1 and affects all versions up to and including 6.3.316. It exists in the plugin's parse_request function and is reachable via the sfgtfi URL path parameter, allowing remote, unauthenticated attackers to read the contents of arbitrary files on the server — including wp-config.php, which typically contains database credentials and WordPress authentication secret keys and salts.
CVSS Score: 9.1 (Critical)
The vulnerability is exploitable by default, since the plugin's optional file_upload_auth setting ships empty (disabled). No prior authentication, special privileges, or user interaction are required to trigger it, and exposure depends only on a form having file uploads enabled somewhere on the site. Although this is an information-disclosure flaw rather than direct code execution, the credentials it exposes — particularly database and WordPress secret-key material in wp-config.php — can be leveraged for full site and database compromise, which is why CosmicBytez Labs is treating it as critical rather than high.
Vulnerability Overview
| Attribute | Value |
|---|---|
| CVE ID | CVE-2026-15896 |
| CVSS Score | 9.1 (Critical) |
| CVSS Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H |
| CWE | CWE-26 — Path Traversal |
| Type | Unauthenticated Arbitrary File Read |
| Attack Vector | Network (no authentication required) |
| Privileges Required | None |
| User Interaction | None |
| Vulnerable Function | parse_request |
| Entry Point | sfgtfi URL path parameter |
| Condition | Exploitable by default; a form with file uploads enabled must exist on the site |
| Exploit Status | No confirmed public proof-of-concept as of this writing; not listed in the CISA KEV catalog |
Affected Versions
| Plugin | Affected Versions | Fixed Version |
|---|---|---|
| Super Forms – Drag & Drop Form Builder | All versions ≤ 6.3.316 | Not confirmed for this CVE — see Remediation |
No source reviewed for this advisory — including the plugin's own GitHub repository and public vulnerability trackers — lists a specific version number as the confirmed fix for CVE-2026-15896 as of publication. A related, separately-tracked flaw in the same plugin and version line, CVE-2026-15983 (arbitrary file/directory deletion), was reportedly fixed in version 6.3.317, but that fix has not been confirmed to also resolve this path traversal issue. Treat any version up to and including 6.3.316 as vulnerable until the vendor explicitly confirms otherwise.
How It Worked
The Core Flaw
Super Forms' parse_request function builds a filesystem path from attacker-controlled input passed through the sfgtfi URL path parameter without adequately sanitizing directory traversal sequences. Because the function does not canonicalize or restrict the resolved path to the plugin's intended upload directory, an attacker can supply a crafted path that resolves outside of it — reaching arbitrary files readable by the web server process, including wp-config.php at the WordPress installation root.
Why It's Exploitable By Default
Super Forms ships an optional setting, file_upload_auth, that is empty by default. When unset, the plugin does not require authentication to reach the vulnerable code path, so the traversal is exploitable by any unauthenticated visitor. Site owners who have explicitly enabled file_upload_auth raise the bar to requiring an authenticated session — but enabling that setting mitigates the unauthenticated exploitation path, it does not fix the underlying traversal bug itself.
Platform-Dependent Exploitation Details
Public technical analysis of the flaw notes that exploitation differs slightly by server operating system:
- Linux: Exploitation requires an existing, real 13-digit timestamp-named directory on the server for the traversal to resolve successfully.
- Windows: The traversal works with any hardcoded 13-digit prefix, without needing a genuine matching directory.
In both cases, the plugin's own file-upload response conveniently discloses the name of the directory it just created — giving an attacker the exact value needed to complete the traversal chain, provided any form on the site has file uploads enabled.
Impact Assessment
| Impact Area | Description |
|---|---|
| Credential Exposure | Reading wp-config.php exposes database host, username, and password, plus WordPress authentication secret keys and salts |
| Database Compromise | Exposed database credentials can enable direct, out-of-band access to the site's full database |
| Session/Cookie Forgery | Exposed authentication salts can enable forgery of valid WordPress authentication cookies |
| Follow-On File Read | The same traversal primitive can be reused to read other sensitive files on the server, not just wp-config.php |
| No Direct Code Execution | This CVE alone does not grant code execution — but the credentials it exposes commonly enable full compromise through other means |
| Default Exposure | Exploitable out of the box on any site where file_upload_auth has not been manually enabled |
Recommendations
For Site Administrators
- Update Super Forms to the latest available version via the WordPress admin dashboard or WP-CLI, and check the plugin's changelog for an explicit reference to this CVE or to "path traversal" / "sfgtfi" fixes:
wp plugin update super-forms wp plugin get super-forms --field=version - Enable the
file_upload_authsetting in Super Forms' settings as an immediate stop-gap — this does not fix the underlying bug but removes the unauthenticated attack path. - Disable file upload fields on any public-facing form that does not strictly need them, since exposure depends on file uploads being enabled somewhere on the site.
- If the plugin is not business-critical and a confirmed fix is not yet available, consider temporarily deactivating it.
For Security Teams
- Rotate WordPress secret keys and salts on any site running an affected version, using:
wp config shuffle-salts - Rotate database credentials referenced in
wp-config.phpif there is any indication the file may have been read by an unauthorized party. - Deploy or update WAF rules (e.g., Wordfence) to detect and block requests containing the
sfgtfiparameter combined with directory traversal sequences (../, URL-encoded equivalents, or 13-digit directory-like values). - Review access and error logs for requests to Super Forms endpoints containing traversal sequences or references to
wp-config.php.
For Users / General Hygiene
- If you manage a WordPress site using Super Forms, treat this as a high-priority patch item even though it is "only" a file-read bug — the credential exposure it enables can cascade into full compromise.
- Keep all WordPress plugins updated and remove any plugins that are no longer actively maintained or needed.
- Use a Web Application Firewall and file-integrity monitoring as defense-in-depth against both this flaw and future disclosures in the same plugin.
Key Takeaways
- CVE-2026-15896 is a critical (CVSS 9.1) unauthenticated path traversal flaw in the Super Forms WordPress plugin, affecting all versions ≤ 6.3.316.
- The flaw lives in the
parse_requestfunction and is triggered via thesfgtfiURL path parameter, exploitable without authentication becausefile_upload_authdefaults to empty. - Successful exploitation allows reading wp-config.php, exposing database credentials and WordPress secret keys/salts — a path to much broader compromise even without direct code execution.
- No confirmed patched version has been identified for this specific CVE as of this advisory; administrators should update to the latest available release and verify against the vendor's changelog.
- This is the second major Super Forms disclosure in 2026 — following CVE-2026-14894, an unauthenticated arbitrary file upload flaw (fixed in 6.3.314) that Wordfence reported blocking over 250,000 exploitation attempts against. A related privilege-escalation flaw, CVE-2026-15897, was disclosed alongside this CVE.
- Enabling
file_upload_authand disabling unnecessary file-upload fields are effective stop-gap mitigations while a confirmed fix is pending.