CVE-2026-15989 | WebRehab Super Forms Plugin up to 6.3.316 on WordPress Register/Login add-on before_email_success_msg role privileges management
A vulnerability was found in WebRehab Super Forms Plugin up to 6.3.316 on WordPress. It has been declared as critical. Impacted is the function before_email_success_msg of the component Register/Login add-on. Executing a manipulation of the argument role can lead to improper privilege management.
This vulnerability is handled as CVE-2026-15989. The attack can be executed remotely. There is not any exploit available.VulDB Recent EntriesRead More