Skip to content
Brief Security & Trust ·

WordPress Super Forms plugin flaw may let low-level users run code

A new NVD record rates the file upload bug 8.8 out of 10 and covers all versions through 6.3.316.

In brief
  • NVD lists CVE-2026-17196 in the Super Forms plugin for WordPress, in versions up to and including 6.3.316. Wordfence scored it 8.8, rated high.
  • The record does not say if a fixed version exists or if attacks are happening.

The US National Vulnerability Database (NVD) published CVE-2026-17196 on 8 October 2026. It covers the Super Forms – Drag & Drop Form Builder plugin for WordPress. The record says every version up to and including 6.3.316 is affected. It says a logged-in user with Subscriber access or higher could upload files that may run as code. That could allow remote code execution, where an attacker runs their own commands on a server. Wordfence, a security firm, scored the flaw 8.8 out of 10, rated high.

The record describes two steps. First, the attacker changes a stored setting for a form through the plugin's save-form request. That request has no permission check and no nonce check (a one-time token that confirms a request is genuine). It still needs a login as a Subscriber or higher. The change lets the attacker pick which file types are allowed. Second, the attacker sends the upload, which the record says needs no login. The record does not say whether a fixed version exists, whether attacks are under way, or how many sites use the plugin. It links a GitHub pull request and a Wordfence page, but does not say what the pull request changes.

Anyone who runs WordPress sites should check which version of Super Forms is installed. The record names a low account level as the starting point, so sites with Subscriber accounts fall inside the scope it describes.

A WebPulse Brief: a short report of an important event, written by the WebPulse Newsroom with AI assistance and checked against the reporting below. When there is more to explain, we follow up with a full story. How we use AI.

Reporting: NIST NVD.