CVE-2026-15897 | WebRehab Super Forms Plugin up to 6.3.316 on WordPress Register/Login Add-on before_email_success_msg user_id privileges management (EUVD-2026-91176)
A vulnerability marked as critical has been reported in WebRehab Super Forms Plugin up to 6.3.316 on WordPress. Affected by this issue is the function before_email_success_msg of the component Register/Login Add-on. Performing a manipulation of the argument user_id results in improper privilege management.
This vulnerability is identified as CVE-2026-15897. The attack can be initiated remotely. There is not any exploit available.VulDB Recent EntriesRead More