{"ok":true,"trend":{"id":706848,"platform":"mastodon","region":"global","key":"🟠 cve-2026-15897 - high (8.8) the super forms – drag & drop form builder plugin for wordpress is vulnerable to privilege","title":"🟠 CVE-2026-15897 - High (8.8) The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege","url":"https://mastodon.social/@thehackerwire/117370033148878706","first_seen":"2026-10-02T07:24:05.046293Z","last_seen":"2026-10-02T07:24:05.046293Z","last_rank":10,"peak_rank":10,"last_volume":0,"peak_volume":0,"seen_count":1,"score":0.72109375,"category_hint":"cybersecurity","section":"technology","category":"cybersecurity","summary":"A high-severity vulnerability, CVE-2026-15897, has been disclosed in the Super Forms Drag & Drop Form Builder plugin for WordPress. The privilege escalation flaw affects all versions up to and including 6.3.316 and stems from the Register & Login add-on's before_email_success_msg() function. Site administrators are being urged to update the plugin to a patched version to avoid potential account takeover risks.","why":"WordPress site owners and security professionals are sharing the disclosure so administrators can patch before exploitation.","tone":"neutral","entities":["Super Forms","WordPress","CVE-2026-15897"],"summarized_at":"2026-10-02T07:25:16.124137Z","meta":{"tag":"infosec","via":"scan","kind":"status","lang":"en","instance":"mastodon.social","tag_uses":959},"nw":null,"promo":null,"kind":null,"importance":null,"hidden":false,"hide_reason":null,"judged_at":null,"title_en":"WordPress Super Forms plugin hit by high-severity privilege escalation flaw","section_name":"Technology","category_name":"Cybersecurity","timeline":[{"captured_at":"2026-10-02T07:24:05.046293Z","rank":10,"volume":0}],"posts":[{"platform":"mastodon","url":"https://mastodon.social/@thehackerwire/117370033148878706","author":"thehackerwire","title":null,"snippet":"🟠 CVE-2026-15897 - High (8.8) The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its registe...…","posted_at":"2026-10-02T07:02:58.084000Z","likes":0}],"elsewhere":[],"window":"7d"}}