Junglewise Threat Intelligence

CVE-2026-28167: Super Forms arbitrary file download in WordPress plugin

CVE-2026-28167 · Severity: high · CVSS 7.5 · Published 2026-08-24

Executive brief

Super Forms is a popular WordPress plugin used to create and manage web forms on WordPress websites. A vulnerability in versions 6.3.315 and earlier allows unauthenticated attackers to download arbitrary files from the affected server, potentially exposing sensitive data such as database credentials, configuration files, and other confidential information without requiring any authentication or user interaction.

Technical details

This is an arbitrary file download vulnerability in the Super Forms WordPress plugin affecting versions 6.3.315 and earlier. The vulnerability is classified as broken access control (OWASP A1) and allows unauthenticated attackers to access and download sensitive files from the server. The attack vector is network-based and requires no authentication, making it highly exploitable. While the exact attack mechanism is not detailed in the advisory, such vulnerabilities typically result from insufficient input validation or path traversal flaws in file download functionality. As of the advisory date, no official patch has been released; mitigation via security plugins or web application firewalls is recommended pending a vendor update.

Affected products

  • Super Forms Super Forms <=6.3.315

Timeline

  • 2026-08-24: disclosed
  • 2026-07-15: other: Reported by VanTastic

References