Horizon Alert
Summary of the vulnerability and why it matters
This critical vulnerability impacts a WordPress form builder plugin, specifically its user registration features. An unauthenticated attacker could potentially gain administrator privileges on affected WordPress sites, which could lead to a complete compromise of the website. The main concern is confirming relevance and exposure.
- Unauthenticated users can gain admin access.
- Critical for any site using this form builder.
- Confirm if your WordPress site is affected.
Attack Path
How an attacker could exploit the issue
An unauthenticated attacker can exploit this vulnerability by submitting a specially crafted request to any public Super Forms registration form. The vulnerable Register & Login add-on mishandles the 'role' parameter during user registration, allowing an attacker to assign themselves the Administrator role. This could lead to complete site compromise.
- No login required.
- Submit form with attacker-chosen role.
- Full site control.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow unauthenticated attackers to gain administrator privileges on a WordPress site. When a Super Forms registration form is publicly accessible and configured with the Register & Login add-on, an attacker could submit specially crafted data to register a new account with the Administrator role. This occurs because the add-on's function does not properly validate the requested user role against administrator-defined settings or perform capability checks before creating the new user account.
- Administrator user role.
- Publicly accessible registration forms.
- Unauthorized site administration.
Operational Fix
Recommended remediation, mitigation, and detection steps
Application owners and platform teams are likely responsible for addressing this critical vulnerability in the Super Forms plugin. The first step is to identify all instances of the affected WordPress plugin across your environment, confirm their reachability and business criticality, and then assign an accountable owner to plan remediation.
- Own the issue and coordinate remediation.
- Verify plugin reachability and business impact.
- Plan and execute the appropriate fix.