Critical Directory Traversal Vulnerability in Super Forms – Drag & Drop Form Builder Plugin for WordPress (CVE-2026-15896)
A critical directory traversal vulnerability (CVE-2026-15896) with a CVSS score of 9.1 affects the Super Forms – Drag & Drop Form Builder plugin for WordPress. This vulnerability allows unauthenticated attackers to read arbitrary files on the server, potentially exposing sensitive information. The vulnerability exists in all versions up to and including 6.3.316 and is exploitable if file upload is enabled on the form. Immediate patching or mitigation is recommended.