Mmastodon TechnologyCybersecurity first seen 7 h ago, last 7 h ago, peak #10
WordPress Super Forms plugin hit by high-severity privilege escalation flaw
Original: 🟠 CVE-2026-15897 - High (8.8) The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege
A high-severity vulnerability, CVE-2026-15897, has been disclosed in the Super Forms Drag & Drop Form Builder plugin for WordPress. The privilege escalation flaw affects all versions up to and including 6.3.316 and stems from the Register & Login add-on's before_email_success_msg() function. Site administrators are being urged to update the plugin to a patched version to avoid potential account takeover risks.
Why now: WordPress site owners and security professionals are sharing the disclosure so administrators can patch before exploitation.
Super FormsWordPressCVE-2026-15897
Evidence
API: https://socialmediatrends-api.osmike.com/v1/trends/706848