Back to Intelligence

CVE-2026-15989, CVE-2026-75957, CVE-2026-92966: Three Critical WordPress Plugin Flaws (CVSS up to 9.8) — Detection and Remediation Guide

SA
Security Arsenal Team
October 1, 2026
11 min read

NVD published three CRITICAL, network-vector vulnerabilities affecting widely deployed WordPress plugins within the last three days: CVE-2026-15989 (CVSS 9.8), CVE-2026-75957 (CVSS 9.8), and CVE-2026-92966 (CVSS 9.1). The most severe — CVE-2026-15989 in the Super Forms – Drag & Drop Form Builder plugin — allows an unauthenticated remote attacker to escalate privileges by abusing the Register & Login add-on's handling of a client-submitted role parameter, effectively handing an attacker the ability to register an administrator account over the network.

WordPress remains the highest-volume attack surface on the public internet. Historically, critical unauthenticated plugin flaws in the WordPress ecosystem are weaponized within hours to days of public disclosure — automated scanners fingerprint vulnerable plugin versions, and mass exploitation typically follows. If you operate WordPress sites — especially marketing sites, SaaS platforms built on multisite, or booking-driven businesses — treat this as an emergency patch event and hunt for prior compromise.

Technical Analysis

Affected Products and Versions

CVEAffected PluginAffected VersionsCVSSVector
CVE-2026-15989Super Forms – Drag & Drop Form Builder (Register & Login add-on)All versions up to and including 6.3.3169.8 CriticalNetwork, unauthenticated
CVE-2026-75957Ultimate Multisite – WordPress Multisite SaaS & WaaS PlatformSee NVD entry for version specifics9.8 CriticalNetwork, unauthenticated
CVE-2026-92966LatePoint – Appointment Booking Plugin (Calendar & Scheduling)See NVD entry for version specifics9.1 CriticalNetwork

CVE-2026-15989 — How the Attack Works

The root cause is a classic trust-boundary violation in the Super Forms Register & Login add-on. The before_email_success_msg() function whitelists the client-submitted role key and copies it directly into the user-data array that is passed to wp_insert_user().

From a defender's perspective, the exploitation chain is straightforward and requires no authentication:

  1. The attacker submits a crafted registration request to a form built with the vulnerable plugin, including a role parameter set to administrator (or another privileged role).
  2. The vulnerable function accepts the client-supplied role without server-side validation against an allowlist of safe roles (e.g., subscriber).
  3. WordPress creates the account with the attacker-specified role — granting full administrative control of the site.
  4. Post-exploitation typically follows a well-worn path: theme/plugin editor abuse or malicious plugin upload to drop a webshell under wp-content/uploads/ or a theme directory, followed by persistence via rogue admin accounts, malicious mu-plugins, or cron-based reinfection.

This is the same anti-pattern that has driven mass compromise campaigns in the WordPress ecosystem for years: unsanitized client input flowing into a privileged WordPress API call.

CVE-2026-75957 — Ultimate Multisite (CVSS 9.8)

The Ultimate Multisite plugin turns WordPress Multisite into a SaaS/WaaS platform — meaning a compromise here is not a single-site event. A flaw in the platform layer can give an attacker leverage across every tenant site in the network: site provisioning, tenant data, and billing-adjacent functionality. Organizations running customer-facing WaaS offerings on this plugin should assume tenant-level blast radius until patched and verified.

CVE-2026-92966 — LatePoint (CVSS 9.1)

The LatePoint appointment booking plugin handles customer PII by design — names, contact details, appointment histories, and frequently payment-adjacent metadata. A critical flaw here puts customer data confidentiality and integrity at risk, and booking plugins are a frequent initial-access vector because they must accept unauthenticated input from the public internet.

Exploitation Status

At the time of writing, these CVEs were published by NVD within the last three days. None are yet listed in the CISA Known Exploited Vulnerabilities catalog, and there is no confirmed public reporting of active in-the-wild exploitation. Do not let that lower your urgency. CVSS 9.8, unauthenticated, network-exploitable WordPress plugin flaws are among the fastest-weaponized vulnerability classes in the industry. The correct posture is: patch immediately, then retro-hunt web and authentication logs for exploitation attempts predating the patch.

Detection & Response

The detections below target the observable behaviors of these attack chains: exploitation requests against the plugins, creation of privileged WordPress accounts, and the most common post-exploitation artifact — PHP webshells dropped into writable directories by the web server process.

Sigma Rules

YAML
---
title: Webshell Dropped in WordPress Writable Directory
id: 3f7a2c91-8b44-4e2d-9a61-cve2026a15989
status: experimental
description: Detects creation of PHP files in WordPress uploads, cache, or other writable directories by the web server process - a hallmark of post-exploitation following WordPress plugin compromise such as CVE-2026-15989.
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-15989
  - https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/04/10
tags:
  - attack.persistence
  - attack.t1505.003
logsource:
  category: file_event
  product: linux
detection:
  selection_path:
    TargetFilename|contains:
      - '/wp-content/uploads/'
      - '/wp-content/cache/'
      - '/wp-content/upgrade/'
      - '/wp-includes/images/'
  selection_ext:
    TargetFilename|endswith:
      - '.php'
      - '.phtml'
      - '.phar'
      - '.php5'
      - '.php7'
  condition: selection_path and selection_ext
falsepositives:
  - Legitimate plugin or media-management functionality writing PHP index files (typically index.php only - exclude exact-match index.php writes if noisy)
level: high
---
title: Web Server Process Spawning Shell or Command Interpreter
id: 8d1e5b62-4c37-4f9a-b2d8-cve2026b75957
status: experimental
description: Detects Apache, Nginx, or PHP-FPM spawning a shell or common post-exploitation tooling - consistent with webshell activity after exploitation of critical WordPress plugin flaws such as CVE-2026-15989, CVE-2026-75957, or CVE-2026-92966.
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-15989
  - https://attack.mitre.org/techniques/T1059/004/
author: Security Arsenal
date: 2026/04/10
tags:
  - attack.execution
  - attack.t1059.004
  - attack.t1505.003
logsource:
  category: process_creation
  product: linux
detection:
  selection_parent:
    ParentImage|endswith:
      - '/php-fpm'
      - '/php-fpm8.1'
      - '/php-fpm8.2'
      - '/php-fpm8.3'
      - '/apache2'
      - '/httpd'
      - '/nginx'
  selection_child:
    Image|endswith:
      - '/sh'
      - '/bash'
      - '/dash'
      - '/curl'
      - '/wget'
      - '/nc'
      - '/ncat'
      - '/python'
      - '/python3'
      - '/perl'
      - '/base64'
  condition: selection_parent and selection_child
falsepositives:
  - Some legitimate WordPress plugins invoke shell commands (image processing, backups) - baseline per host and whitelist known plugin behavior
level: high
---
title: Suspicious WordPress User Registration with Role Parameter
id: 51c9d4a7-2e68-4b1f-9c73-cve2026c92966
status: experimental
description: Detects HTTP POST requests to WordPress endpoints containing a client-submitted role parameter - the exploitation primitive of CVE-2026-15989, where Super Forms passes the role key to wp_insert_user(). Apply against web server access logs ingested as proxy/firewall logs.
references:
  - https://nvd.nist.gov/vuln/detail/CVE-2026-15989
  - https://attack.mitre.org/techniques/T1136/
author: Security Arsenal
date: 2026/04/10
tags:
  - attack.persistence
  - attack.t1136.001
  - attack.initial_access
  - attack.t1190
logsource:
  category: webserver
detection:
  selection_method:
    cs-method: 'POST'
  selection_body:
    cs-uri-query|contains:
      - 'role=administrator'
      - 'role%5B%5D=administrator'
      - 'role=editor'
  selection_uri:
    cs-uri-stem|contains:
      - '/wp-admin/admin-ajax.php'
      - '/wp-json/'
      - 'super-forms'
      - 'super_forms'
  condition: selection_method and selection_body and selection_uri
falsepositives:
  - Legitimate admin-ajax operations from authenticated administrators - correlate with source IP reputation and authenticated session absence
level: high

KQL — Microsoft Sentinel / Defender

WordPress hosts typically report into Sentinel via Syslog/CEF ingestion of Apache or Nginx access logs, plus auditd or Defender for Endpoint on the host itself. The query below hunts both the exploitation primitive (role parameter in POST bodies/URIs against the vulnerable plugins) and the post-exploitation behavior (web server spawning shells).

KQL — Microsoft Sentinel / Defender
// Hunt 1: Exploitation attempts - role parameter abuse against WordPress plugin endpoints (CVE-2026-15989)
let lookback = 14d;
union isfuzzy=true
    (CommonSecurityLog
    | where TimeGenerated > ago(lookback)
    | where RequestMethod == "POST"
    | where RequestURL has_any ("admin-ajax.php", "wp-json", "super-forms", "latepoint", "ultimate-multisite", "wp-signup.php", "wp-login.php")
    | where RequestURL has_any ("role=administrator", "role%5B%5D=administrator", "role=editor")
    | project TimeGenerated, SourceIP, RequestURL, RequestMethod, DeviceAction, SourceHostName),
    (Syslog
    | where TimeGenerated > ago(lookback)
    | where SyslogMessage has "POST"
    | where SyslogMessage has_any ("admin-ajax.php", "wp-json", "super-forms", "latepoint", "ultimate-multisite")
    | where SyslogMessage has_any ("role=administrator", "role=editor")
    | project TimeGenerated, HostIP, SyslogMessage, Computer);
// Hunt 2: Post-exploitation - web server user spawning shells/tools on Linux WordPress hosts
SecurityEvent
| where TimeGenerated > ago(14d)
| where EventID == 4688
| where ParentProcessName has_any ("php-fpm", "apache2", "httpd", "nginx")
| where NewProcessName has_any ("\\sh", "\\bash", "\\curl", "\\wget", "\\nc", "\\python", "\\perl")
| project TimeGenerated, Computer, ParentProcessName, NewProcessName, CommandLine, Account
| order by TimeGenerated desc;
// Hunt 3: Rogue admin account creation - review WordPress user creation events if audit logging (e.g., WP activity log plugin) forwards to Syslog
Syslog
| where TimeGenerated > ago(14d)
| where SyslogMessage has_any ("user_register", "wp_insert_user", "added user", "new user")
| where SyslogMessage has_any ("administrator", "role")
| project TimeGenerated, Computer, SyslogMessage
| order by TimeGenerated desc;

Velociraptor VQL

Use this hunt artifact across WordPress hosts to surface webshells recently written to writable directories and suspicious processes parented to the web server stack. Pair with a timeline of your patch date — any PHP file in uploads/ modified before patching is suspect.

VQL — Velociraptor
-- Hunt: Webshell artifacts and post-exploitation processes on WordPress hosts
-- Artifact 1 logic: Recently modified PHP files in writable WordPress directories
SELECT FullPath, Mtime, Size, Mode
FROM glob(globs=['/var/www/**/wp-content/uploads/**/*.php',
                 '/var/www/**/wp-content/cache/**/*.php',
                 '/var/www/**/wp-content/upgrade/**/*.php',
                 '/srv/www/**/wp-content/uploads/**/*.php'])
WHERE NOT FullPath =~ 'index.php$'
ORDER BY Mtime DESC

-- Artifact 2 logic: Processes spawned by the web server stack
SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Username =~ 'www-data|apache|nginx'
  AND Name =~ 'sh|bash|dash|curl|wget|nc|ncat|python|perl'

Remediation & Verification Script

Run on each WordPress host (or via your configuration management fleet-wide) to inventory the vulnerable plugins, identify versions, flag likely webshell artifacts, and check for rogue administrator accounts in the database.

Bash / Shell
#!/bin/bash
# CVE-2026-15989 / CVE-2026-75957 / CVE-2026-92966 - WordPress plugin inventory and triage
# Run as root or with sudo on each WordPress host.

WP_ROOTS="/var/www /srv/www /home"

echo "=== [1] Locate vulnerable plugin installations and versions ==="
for root in $WP_ROOTS; do
  find "$root" -type d \( -name "super-forms" -o -name "ultimate-multisite" -o -name "latepoint" \) 2>/dev/null
  find "$root" -type f -path "*/super-forms/super-forms.php" 2>/dev/null | while read f; do
    echo "--- $f"; grep -m1 "Version:" "$f"
  done
  find "$root" -type f -path "*/latepoint/latepoint.php" 2>/dev/null | while read f; do
    echo "--- $f"; grep -m1 "Version:" "$f"
  done
done
# Any Super Forms version <= 6.3.316 is VULNERABLE to CVE-2026-15989

echo "=== [2] Hunt for PHP webshells in writable directories ==="
find /var/www /srv/www -type f \( -name "*.php" -o -name "*.phtml" -o -name "*.phar" \) \
  -path "*/wp-content/uploads/*" 2>/dev/null | grep -v "/index.php$"

echo "=== [3] Flag recently modified PHP files (last 14 days) in wp-content ==="
find /var/www /srv/www -type f -name "*.php" -path "*/wp-content/*" -mtime -14 2>/dev/null

echo "=== [4] Audit WordPress administrator accounts (requires wp-cli) ==="
for root in $WP_ROOTS; do
  find "$root" -name "wp-config.php" 2>/dev/null | while read cfg; do
    dir=$(dirname "$cfg")
    echo "--- Site: $dir"
    sudo -u www-data wp user list --role=administrator --fields=ID,user_login,user_email,user_registered --path="$dir" 2>/dev/null
  done
done
# Investigate any administrator account you do not recognize or with a recent registration date.

echo "=== [5] Check web server child processes for shells ==="
ps auxf | grep -E "(apache2|httpd|nginx|php-fpm)" -A2 | grep -E "(sh|bash|curl|wget|nc |python|perl)"

echo "=== Done. Correlate findings with web access logs for POSTs containing 'role=administrator'. ==="

Remediation

  1. Patch immediately. Update Super Forms – Drag & Drop Form Builder to a version newer than 6.3.316 as soon as the vendor releases a fixed build — check the plugin's WordPress.org page and the vendor changelog daily if a fix is not yet live. Apply the same treatment to Ultimate Multisite and LatePoint per the version guidance in each NVD entry:
  2. If no patch is available, disable and remove the vulnerable plugin. For Super Forms specifically, if the form functionality is business-critical, deactivate the Register & Login add-on until a fixed version ships — that add-on contains the vulnerable before_email_success_msg() code path. A disabled plugin's code should not be reachable; do not rely on "the form isn't on a public page" as a mitigation.
  3. Enforce server-side role validation. As defense-in-depth, ensure no registration flow on your sites permits client-supplied role assignment. Where custom code exists, force the role server-side (e.g., hardcode subscriber) and never pass user-controlled input into wp_insert_user() role fields.
  4. Hunt before you declare done. Assume exploitation may have predated patching. Review web access logs for POST requests containing role=administrator, audit all WordPress administrator accounts (creation date, email, last login), and scan writable directories for PHP files per the script above. Rogue admin accounts and mu-plugins are the most common persistence mechanisms in WordPress compromises.
  5. Harden the platform. Deploy a WAF rule (ModSecurity or your CDN/WAF provider) blocking POST bodies with role=administrator to WordPress endpoints as a virtual patch; disable the theme/plugin file editor (define('DISALLOW_FILE_EDIT', true); in wp-config.php); restrict PHP execution in wp-content/uploads/ via web server configuration; and ensure files in uploads/ are never executable.
  6. For Ultimate Multisite operators: treat this as a cross-tenant incident. Review network-site provisioning logs and tenant admin inventories across the entire multisite network, not just the primary site.
  7. Monitor CISA KEV. None of these CVEs are on the KEV catalog at publication time, but CVSS 9.8 unauthenticated WordPress flaws are strong candidates. Subscribe to KEV updates and re-prioritize accordingly.

Related Resources

Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub

Is your security operations ready?

Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.