The US National Vulnerability Database (NVD) published CVE-2026-17196 on 8 October 2026. It covers the Super Forms – Drag & Drop Form Builder plugin for WordPress. The record says every version up to and including 6.3.316 is affected. It says a logged-in user with Subscriber access or higher could upload files that may run as code. That could allow remote code execution, where an attacker runs their own commands on a server. Wordfence, a security firm, scored the flaw 8.8 out of 10, rated high.
The record describes two steps. First, the attacker changes a stored setting for a form through the plugin's save-form request. That request has no permission check and no nonce check (a one-time token that confirms a request is genuine). It still needs a login as a Subscriber or higher. The change lets the attacker pick which file types are allowed. Second, the attacker sends the upload, which the record says needs no login. The record does not say whether a fixed version exists, whether attacks are under way, or how many sites use the plugin. It links a GitHub pull request and a Wordfence page, but does not say what the pull request changes.
Anyone who runs WordPress sites should check which version of Super Forms is installed. The record names a low account level as the starting point, so sites with Subscriber accounts fall inside the scope it describes.