Answer in brief
CVE-2026-15896 records a Critical severity (CVSS 9.1) vulnerability in Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter. The current sources do not mark it as known exploited. The current feed maps WebRehab/Super Forms – Drag & Drop Form Builder (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 9.1. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps WebRehab/Super Forms – Drag & Drop Form Builder (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| WebRehab/Super Forms – Drag & Drop Form Buildergeneric | >=0 <=6.3.316 | Not reported |
Published upstream
Oct 2, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 2, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 2, 2026
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin's file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form.
Quoted source text, attributed separately from HOL analysis.