Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-15989 β€” Python PoC scanner for CVE-2026-15989, exploiting unauthenticated role injection in WordPress Super Forms to create admin accounts and verify access. | Kitploit
Tools/GitHubGitHub/antid00t/cve-2026-15989
Privilege EscalationVulnerability ScannersPassword AttacksExploitationScripting & AutomationWeb Application ExploitationWeb SecurityPenetration TestingRed Teaming
GitHubantid00t/cve-2026-15989

CVE-2026-15989

Python PoC scanner for CVE-2026-15989, exploiting unauthenticated role injection in WordPress Super Forms to create admin accounts and verify access.

14h 20m agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share
View Repository
                  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ–ˆβ•—   β–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—   β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—   β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•—
                 β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•— β–ˆβ–ˆβ–ˆβ–ˆβ•—  β–ˆβ–ˆβ•‘ β•šβ•β•β–ˆβ–ˆβ•”β•β•β• β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•— β–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ•— β–ˆβ–ˆβ•”β•β–ˆβ–ˆβ–ˆβ–ˆβ•— β•šβ•β•β–ˆβ–ˆβ•”β•β•β•
              β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•”β–ˆβ–ˆβ•— β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘β–ˆβ–ˆβ•”β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ•‘
              β–ˆβ–ˆβ•”β•β•β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘β•šβ–ˆβ–ˆβ•—β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ–ˆβ–ˆβ•”β•β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ•‘
              β–ˆβ–ˆβ•‘  β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ•‘ β•šβ–ˆβ–ˆβ–ˆβ–ˆβ•‘    β–ˆβ–ˆβ•‘    β–ˆβ–ˆβ•‘ β–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β• β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β• β•šβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ–ˆβ•”β•    β–ˆβ–ˆβ•‘
              β•šβ•β•  β•šβ•β• β•šβ•β•  β•šβ•β•β•β•    β•šβ•β•    β•šβ•β• β•šβ•β•β•β•β•β•   β•šβ•β•β•β•β•β•   β•šβ•β•β•β•β•β•     β•šβ•β•

πŸ’‰ Super Forms β€” Multi-Lab PrivEsc Scanner

CVE-2026-15989 Β· Unauthenticated Admin Account Creation

                                       Β» E X P L O I T S Β«

Python 3.8+ CVSS 9.8 CRITICAL WordPress Engine Banner style Telegram

πŸ”₯ Fingerprint-free auto-discovery Β· Validation-aware payloads Β· Zero authentication Β· Honest classification

screen02


🎯 Target

WordPress PluginSuper Forms – Drag & Drop Form Builder (Register & Login add-on)
Affected Version<= 6.3.316
Patched Version6.3.317
Authentication❌ None required β€” any published registration form is enough
CVSS9.8 CRITICAL

⚑ The Chains

πŸ‘‘ CVE-2026-15989 β€” Whitelisted role key β†’ Administrator Creation
GET admin-ajax.php?action=super_create_nonce ──► _sfs_id session + sf_nonce
        β”‚
POST admin-ajax.php  action=super_submit_form  data=<JSON>
        β”‚
      before_email_success_msg()  (Register & Login add-on)
        β”‚
$other_userdata = array( ..., 'role', ... )   ◄── client key whitelisted
        β”‚
$data['role']['value']  ──►  $userdata['role']   (register_user_role overwritten)
        β”‚
wp_insert_user()  ──►  πŸ”₯ administrator account, zero authentication

The add-on copies $data['role']['value'] straight into the user-data array without validating it against the admin-configured register_user_role, without an allow-list and without any capability check β€” a single injected "role": {"value":"administrator"} field wins.

🎟️ Login Proof β€” Activation-Gate Bypass
POST wp-login.php   log / pwd / testcookie
        β”‚                    + action=super_submit_form   ◄── the magic field
        β”‚
check_user_login_status()  ──► pending/blocked gate SKIPPED
        β”‚
GET /wp-admin/users.php
        β”‚
200 = administrator proven  Β·  403 = subscriber (patched build)

The add-on only enforces its email-activation / moderation gate when the POST action is NOT super_submit_form β€” so the same form action that registers the user also unlocks logging into it, even before any email verification.

🧨 FULL Mode β€” Two-Phase Form-ID Brute (no fingerprinting needed)
discovery empty (REST Β· sitemap Β· links Β· ?page_id probe)
        β”‚
PHASE 1 β€” form-ID sweep 1..50, minimal payload, OWN SESSION PER ID
        β”‚                       (shared sessions would invalidate each nonce)
        β”‚
'required fields' reject ──► PHASE 2 β€” REST markup fetch ──► full payload retry
        β”‚
every accepted candidate ──► login proof per id
        β”‚
contact form? ──► UNVERIFIED (never a false positive)
registration? ──► πŸ‘‘ verified administrator

Non-registration forms also answer error:false, so every accepted id is only a candidate until the credential is proven with a real login.

πŸš€ Quick Start

# zero dependencies β€” pure Python 3 stdlib (rich is optional, for the console)
python3 cve-2026-15989_poc.py --list labs.txt --output results.txt

# tuned concurrency / timeout
python3 cve-2026-15989_poc.py --list labs.txt --threads 20 --timeout 15 -o results.txt

# FULL MODE: discovery + role injection + login proof + form-ID brute (1..50)
python3 cve-2026-15989_poc.py --list labs.txt --full --output results.txt

labs.txt β€” one base URL per line:

http://localhost
http://192.168.56.101/lab-wp
https://10.0.0.5:8443/lab        # self-signed TLS is handled automatically
# comments and blank lines are ignored

πŸ› οΈ Options

OptionDescription
--list FILEtarget file β€” one URL per line (required)
--output, -o FILEhit-list β€” only VULNERABLE targets written live (ANSI-free)
--threads Nconcurrent target workers (default 10)
--timeout Nper-request socket timeout in seconds (default 10)
--fullrun the WHOLE chain β€” adds the form-ID brute fallback (accounts WILL be created on vulnerable targets)

🧾 Result States

StateMeaning
VULNERABLEaccount created and wp-admin administrator access proven (200)
NOT-VULNERABLElogin OK but admin pages 403 β€” role ignored β†’ patched build
UNVERIFIEDsubmission accepted but login rejected (locked/pending account or non-registration form) β€” never reported as a silent false positive
BLOCKEDsubmission rejected (reCAPTCHA, CSRF, required fields, honeypot…)
ERRORunreachable target / DNS failure β€” reported with the exact cause

✨ Features

  • πŸ” Fingerprint-free auto-discovery β€” REST rendered content (wp-json + ?rest_route= fallback) β†’ sitemap index β†’ 40+ multi-language registration paths (/register, /kayit-ol, /registrieren…) β†’ ?page_id=N probe; works with any theme, page builder and permalink style
  • 🧬 Validation-aware payload synthesis β€” every rendered field is auto-filled the way the browser would: own defaults, textarea content, dropdown/checkbox/radio options, data-validation types (email, number, date, time, phone, IBAN, color, URL)
  • 🎟️ Automated CSRF β€” nopriv super_create_nonce bound to the _sfs_id session; brute attempts get their OWN session so nonces never invalidate each other
  • πŸ‘‘ Honest classification β€” VULNERABLE only when wp-admin access is proven; patched builds are separated by the 403 probe; locked accounts surface as UNVERIFIED
  • πŸ₯· Activation-gate bypass β€” login proof carries action=super_submit_form, skipping the add-on's email-verification / moderation gate
  • 🧨 FULL mode β€” two-phase form-ID brute with per-id login proof (contact forms can never false-positive)
  • πŸ›‘οΈ URL hardening β€” theme template links ({{ data.url }}), control characters and IDN/Turkish-slug hosts are sanitized automatically
  • πŸ“ Clean hit-list β€” --output records ONLY confirmed targets, appended live, always plain text (grep/parse friendly)
  • πŸ“Š Rich console β€” antid00t-style ANSI Shadow banner, live scoreboard, summary table; graceful plain-text fallback without rich
  • 🐍 Zero dependencies β€” pure Python 3 stdlib (rich is optional eye-candy)

πŸ“‹ Requirements

Download Tool