MikeTrendsTrends right now

Mmastodon TechnologyCybersecurity first seen 6 h ago, last 6 h ago, peak #10

WordPress Super Forms plugin hit by high-severity privilege escalation flaw

Original: 🟠 CVE-2026-15897 - High (8.8) The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege

A high-severity vulnerability, CVE-2026-15897, has been disclosed in the Super Forms Drag & Drop Form Builder plugin for WordPress. The privilege escalation flaw affects all versions up to and including 6.3.316 and stems from the Register & Login add-on's before_email_success_msg() function. Site administrators are being urged to update the plugin to a patched version to avoid potential account takeover risks.

Why now: WordPress site owners and security professionals are sharing the disclosure so administrators can patch before exploitation.

Super FormsWordPressCVE-2026-15897

Open on mastodon →

Evidence

API: https://socialmediatrends-api.osmike.com/v1/trends/706848