The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin's file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The Super Forms – Drag & Drop Form Builder plugin for WordPress contains a critical directory traversal vulnerability in its parse_request function that allows unauthenticated attackers to read arbitrary files from the server. With a CVSS score of 9.1, this vulnerability poses an immediate risk to any WordPress installation using versions up to 6.3.316 with the default configuration. The vulnerability is particularly dangerous because the 'file_upload_auth' setting defaults to empty (disabled), meaning attackers require no credentials to exploit it. Affected organizations could have sensitive files exposed, including database credentials, API keys, configuration files, and other confidential data stored on the web server.
While this CVE currently maps to zero Casky skills due to the absence of MITRE ATT&CK technique classifications, practitioners can still leverage Casky's Claude-powered reasoning to detect exploitation patterns by monitoring for suspicious HTTP requests to the form builder plugin's endpoints with path traversal sequences (../, ..\, unicode encoding variations). Security teams should focus detection efforts on anomalous file access requests, particularly those targeting sensitive locations like wp-config.php, .env files, and other configuration resources. Extended reasoning analysis would help correlate request patterns with backend file system access logs to identify reconnaissance activity before sensitive data exfiltration occurs. Implementing immediate patching, enforcing the 'file_upload_auth' setting, or disabling the plugin until updates are applied remains critical until MITRE technique mappings enable more granular behavioral detection within the Casky platform.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-15896. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation