NVD published three CRITICAL, network-vector vulnerabilities affecting widely deployed WordPress plugins within the last three days: CVE-2026-15989 (CVSS 9.8), CVE-2026-75957 (CVSS 9.8), and CVE-2026-92966 (CVSS 9.1). The most severe — CVE-2026-15989 in the Super Forms – Drag & Drop Form Builder plugin — allows an unauthenticated remote attacker to escalate privileges by abusing the Register & Login add-on's handling of a client-submitted role parameter, effectively handing an attacker the ability to register an administrator account over the network.
WordPress remains the highest-volume attack surface on the public internet. Historically, critical unauthenticated plugin flaws in the WordPress ecosystem are weaponized within hours to days of public disclosure — automated scanners fingerprint vulnerable plugin versions, and mass exploitation typically follows. If you operate WordPress sites — especially marketing sites, SaaS platforms built on multisite, or booking-driven businesses — treat this as an emergency patch event and hunt for prior compromise.
Technical Analysis
Affected Products and Versions
| CVE | Affected Plugin | Affected Versions | CVSS | Vector |
|---|---|---|---|---|
| CVE-2026-15989 | Super Forms – Drag & Drop Form Builder (Register & Login add-on) | All versions up to and including 6.3.316 | 9.8 Critical | Network, unauthenticated |
| CVE-2026-75957 | Ultimate Multisite – WordPress Multisite SaaS & WaaS Platform | See NVD entry for version specifics | 9.8 Critical | Network, unauthenticated |
| CVE-2026-92966 | LatePoint – Appointment Booking Plugin (Calendar & Scheduling) | See NVD entry for version specifics | 9.1 Critical | Network |
CVE-2026-15989 — How the Attack Works
The root cause is a classic trust-boundary violation in the Super Forms Register & Login add-on. The before_email_success_msg() function whitelists the client-submitted role key and copies it directly into the user-data array that is passed to wp_insert_user().
From a defender's perspective, the exploitation chain is straightforward and requires no authentication:
- The attacker submits a crafted registration request to a form built with the vulnerable plugin, including a
roleparameter set toadministrator(or another privileged role). - The vulnerable function accepts the client-supplied role without server-side validation against an allowlist of safe roles (e.g.,
subscriber). - WordPress creates the account with the attacker-specified role — granting full administrative control of the site.
- Post-exploitation typically follows a well-worn path: theme/plugin editor abuse or malicious plugin upload to drop a webshell under
wp-content/uploads/or a theme directory, followed by persistence via rogue admin accounts, malicious mu-plugins, or cron-based reinfection.
This is the same anti-pattern that has driven mass compromise campaigns in the WordPress ecosystem for years: unsanitized client input flowing into a privileged WordPress API call.
CVE-2026-75957 — Ultimate Multisite (CVSS 9.8)
The Ultimate Multisite plugin turns WordPress Multisite into a SaaS/WaaS platform — meaning a compromise here is not a single-site event. A flaw in the platform layer can give an attacker leverage across every tenant site in the network: site provisioning, tenant data, and billing-adjacent functionality. Organizations running customer-facing WaaS offerings on this plugin should assume tenant-level blast radius until patched and verified.
CVE-2026-92966 — LatePoint (CVSS 9.1)
The LatePoint appointment booking plugin handles customer PII by design — names, contact details, appointment histories, and frequently payment-adjacent metadata. A critical flaw here puts customer data confidentiality and integrity at risk, and booking plugins are a frequent initial-access vector because they must accept unauthenticated input from the public internet.
Exploitation Status
At the time of writing, these CVEs were published by NVD within the last three days. None are yet listed in the CISA Known Exploited Vulnerabilities catalog, and there is no confirmed public reporting of active in-the-wild exploitation. Do not let that lower your urgency. CVSS 9.8, unauthenticated, network-exploitable WordPress plugin flaws are among the fastest-weaponized vulnerability classes in the industry. The correct posture is: patch immediately, then retro-hunt web and authentication logs for exploitation attempts predating the patch.
Detection & Response
The detections below target the observable behaviors of these attack chains: exploitation requests against the plugins, creation of privileged WordPress accounts, and the most common post-exploitation artifact — PHP webshells dropped into writable directories by the web server process.
Sigma Rules
---
title: Webshell Dropped in WordPress Writable Directory
id: 3f7a2c91-8b44-4e2d-9a61-cve2026a15989
status: experimental
description: Detects creation of PHP files in WordPress uploads, cache, or other writable directories by the web server process - a hallmark of post-exploitation following WordPress plugin compromise such as CVE-2026-15989.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-15989
- https://attack.mitre.org/techniques/T1505/003/
author: Security Arsenal
date: 2026/04/10
tags:
- attack.persistence
- attack.t1505.003
logsource:
category: file_event
product: linux
detection:
selection_path:
TargetFilename|contains:
- '/wp-content/uploads/'
- '/wp-content/cache/'
- '/wp-content/upgrade/'
- '/wp-includes/images/'
selection_ext:
TargetFilename|endswith:
- '.php'
- '.phtml'
- '.phar'
- '.php5'
- '.php7'
condition: selection_path and selection_ext
falsepositives:
- Legitimate plugin or media-management functionality writing PHP index files (typically index.php only - exclude exact-match index.php writes if noisy)
level: high
---
title: Web Server Process Spawning Shell or Command Interpreter
id: 8d1e5b62-4c37-4f9a-b2d8-cve2026b75957
status: experimental
description: Detects Apache, Nginx, or PHP-FPM spawning a shell or common post-exploitation tooling - consistent with webshell activity after exploitation of critical WordPress plugin flaws such as CVE-2026-15989, CVE-2026-75957, or CVE-2026-92966.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-15989
- https://attack.mitre.org/techniques/T1059/004/
author: Security Arsenal
date: 2026/04/10
tags:
- attack.execution
- attack.t1059.004
- attack.t1505.003
logsource:
category: process_creation
product: linux
detection:
selection_parent:
ParentImage|endswith:
- '/php-fpm'
- '/php-fpm8.1'
- '/php-fpm8.2'
- '/php-fpm8.3'
- '/apache2'
- '/httpd'
- '/nginx'
selection_child:
Image|endswith:
- '/sh'
- '/bash'
- '/dash'
- '/curl'
- '/wget'
- '/nc'
- '/ncat'
- '/python'
- '/python3'
- '/perl'
- '/base64'
condition: selection_parent and selection_child
falsepositives:
- Some legitimate WordPress plugins invoke shell commands (image processing, backups) - baseline per host and whitelist known plugin behavior
level: high
---
title: Suspicious WordPress User Registration with Role Parameter
id: 51c9d4a7-2e68-4b1f-9c73-cve2026c92966
status: experimental
description: Detects HTTP POST requests to WordPress endpoints containing a client-submitted role parameter - the exploitation primitive of CVE-2026-15989, where Super Forms passes the role key to wp_insert_user(). Apply against web server access logs ingested as proxy/firewall logs.
references:
- https://nvd.nist.gov/vuln/detail/CVE-2026-15989
- https://attack.mitre.org/techniques/T1136/
author: Security Arsenal
date: 2026/04/10
tags:
- attack.persistence
- attack.t1136.001
- attack.initial_access
- attack.t1190
logsource:
category: webserver
detection:
selection_method:
cs-method: 'POST'
selection_body:
cs-uri-query|contains:
- 'role=administrator'
- 'role%5B%5D=administrator'
- 'role=editor'
selection_uri:
cs-uri-stem|contains:
- '/wp-admin/admin-ajax.php'
- '/wp-json/'
- 'super-forms'
- 'super_forms'
condition: selection_method and selection_body and selection_uri
falsepositives:
- Legitimate admin-ajax operations from authenticated administrators - correlate with source IP reputation and authenticated session absence
level: high
KQL — Microsoft Sentinel / Defender
WordPress hosts typically report into Sentinel via Syslog/CEF ingestion of Apache or Nginx access logs, plus auditd or Defender for Endpoint on the host itself. The query below hunts both the exploitation primitive (role parameter in POST bodies/URIs against the vulnerable plugins) and the post-exploitation behavior (web server spawning shells).
// Hunt 1: Exploitation attempts - role parameter abuse against WordPress plugin endpoints (CVE-2026-15989)
let lookback = 14d;
union isfuzzy=true
(CommonSecurityLog
| where TimeGenerated > ago(lookback)
| where RequestMethod == "POST"
| where RequestURL has_any ("admin-ajax.php", "wp-json", "super-forms", "latepoint", "ultimate-multisite", "wp-signup.php", "wp-login.php")
| where RequestURL has_any ("role=administrator", "role%5B%5D=administrator", "role=editor")
| project TimeGenerated, SourceIP, RequestURL, RequestMethod, DeviceAction, SourceHostName),
(Syslog
| where TimeGenerated > ago(lookback)
| where SyslogMessage has "POST"
| where SyslogMessage has_any ("admin-ajax.php", "wp-json", "super-forms", "latepoint", "ultimate-multisite")
| where SyslogMessage has_any ("role=administrator", "role=editor")
| project TimeGenerated, HostIP, SyslogMessage, Computer);
// Hunt 2: Post-exploitation - web server user spawning shells/tools on Linux WordPress hosts
SecurityEvent
| where TimeGenerated > ago(14d)
| where EventID == 4688
| where ParentProcessName has_any ("php-fpm", "apache2", "httpd", "nginx")
| where NewProcessName has_any ("\\sh", "\\bash", "\\curl", "\\wget", "\\nc", "\\python", "\\perl")
| project TimeGenerated, Computer, ParentProcessName, NewProcessName, CommandLine, Account
| order by TimeGenerated desc;
// Hunt 3: Rogue admin account creation - review WordPress user creation events if audit logging (e.g., WP activity log plugin) forwards to Syslog
Syslog
| where TimeGenerated > ago(14d)
| where SyslogMessage has_any ("user_register", "wp_insert_user", "added user", "new user")
| where SyslogMessage has_any ("administrator", "role")
| project TimeGenerated, Computer, SyslogMessage
| order by TimeGenerated desc;
Velociraptor VQL
Use this hunt artifact across WordPress hosts to surface webshells recently written to writable directories and suspicious processes parented to the web server stack. Pair with a timeline of your patch date — any PHP file in uploads/ modified before patching is suspect.
-- Hunt: Webshell artifacts and post-exploitation processes on WordPress hosts
-- Artifact 1 logic: Recently modified PHP files in writable WordPress directories
SELECT FullPath, Mtime, Size, Mode
FROM glob(globs=['/var/www/**/wp-content/uploads/**/*.php',
'/var/www/**/wp-content/cache/**/*.php',
'/var/www/**/wp-content/upgrade/**/*.php',
'/srv/www/**/wp-content/uploads/**/*.php'])
WHERE NOT FullPath =~ 'index.php$'
ORDER BY Mtime DESC
-- Artifact 2 logic: Processes spawned by the web server stack
SELECT Pid, Ppid, Name, CommandLine, Exe, Username, CreateTime
FROM pslist()
WHERE Username =~ 'www-data|apache|nginx'
AND Name =~ 'sh|bash|dash|curl|wget|nc|ncat|python|perl'
Remediation & Verification Script
Run on each WordPress host (or via your configuration management fleet-wide) to inventory the vulnerable plugins, identify versions, flag likely webshell artifacts, and check for rogue administrator accounts in the database.
#!/bin/bash
# CVE-2026-15989 / CVE-2026-75957 / CVE-2026-92966 - WordPress plugin inventory and triage
# Run as root or with sudo on each WordPress host.
WP_ROOTS="/var/www /srv/www /home"
echo "=== [1] Locate vulnerable plugin installations and versions ==="
for root in $WP_ROOTS; do
find "$root" -type d \( -name "super-forms" -o -name "ultimate-multisite" -o -name "latepoint" \) 2>/dev/null
find "$root" -type f -path "*/super-forms/super-forms.php" 2>/dev/null | while read f; do
echo "--- $f"; grep -m1 "Version:" "$f"
done
find "$root" -type f -path "*/latepoint/latepoint.php" 2>/dev/null | while read f; do
echo "--- $f"; grep -m1 "Version:" "$f"
done
done
# Any Super Forms version <= 6.3.316 is VULNERABLE to CVE-2026-15989
echo "=== [2] Hunt for PHP webshells in writable directories ==="
find /var/www /srv/www -type f \( -name "*.php" -o -name "*.phtml" -o -name "*.phar" \) \
-path "*/wp-content/uploads/*" 2>/dev/null | grep -v "/index.php$"
echo "=== [3] Flag recently modified PHP files (last 14 days) in wp-content ==="
find /var/www /srv/www -type f -name "*.php" -path "*/wp-content/*" -mtime -14 2>/dev/null
echo "=== [4] Audit WordPress administrator accounts (requires wp-cli) ==="
for root in $WP_ROOTS; do
find "$root" -name "wp-config.php" 2>/dev/null | while read cfg; do
dir=$(dirname "$cfg")
echo "--- Site: $dir"
sudo -u www-data wp user list --role=administrator --fields=ID,user_login,user_email,user_registered --path="$dir" 2>/dev/null
done
done
# Investigate any administrator account you do not recognize or with a recent registration date.
echo "=== [5] Check web server child processes for shells ==="
ps auxf | grep -E "(apache2|httpd|nginx|php-fpm)" -A2 | grep -E "(sh|bash|curl|wget|nc |python|perl)"
echo "=== Done. Correlate findings with web access logs for POSTs containing 'role=administrator'. ==="
Remediation
- Patch immediately. Update Super Forms – Drag & Drop Form Builder to a version newer than 6.3.316 as soon as the vendor releases a fixed build — check the plugin's WordPress.org page and the vendor changelog daily if a fix is not yet live. Apply the same treatment to Ultimate Multisite and LatePoint per the version guidance in each NVD entry:
- If no patch is available, disable and remove the vulnerable plugin. For Super Forms specifically, if the form functionality is business-critical, deactivate the Register & Login add-on until a fixed version ships — that add-on contains the vulnerable
before_email_success_msg()code path. A disabled plugin's code should not be reachable; do not rely on "the form isn't on a public page" as a mitigation. - Enforce server-side role validation. As defense-in-depth, ensure no registration flow on your sites permits client-supplied role assignment. Where custom code exists, force the role server-side (e.g., hardcode
subscriber) and never pass user-controlled input intowp_insert_user()role fields. - Hunt before you declare done. Assume exploitation may have predated patching. Review web access logs for POST requests containing
role=administrator, audit all WordPress administrator accounts (creation date, email, last login), and scan writable directories for PHP files per the script above. Rogue admin accounts and mu-plugins are the most common persistence mechanisms in WordPress compromises. - Harden the platform. Deploy a WAF rule (ModSecurity or your CDN/WAF provider) blocking POST bodies with
role=administratorto WordPress endpoints as a virtual patch; disable the theme/plugin file editor (define('DISALLOW_FILE_EDIT', true);inwp-config.php); restrict PHP execution inwp-content/uploads/via web server configuration; and ensure files inuploads/are never executable. - For Ultimate Multisite operators: treat this as a cross-tenant incident. Review network-site provisioning logs and tenant admin inventories across the entire multisite network, not just the primary site.
- Monitor CISA KEV. None of these CVEs are on the KEV catalog at publication time, but CVSS 9.8 unauthenticated WordPress flaws are strong candidates. Subscribe to KEV updates and re-prioritize accordingly.
Related Resources
Security Arsenal Penetration Testing Services AlertMonitor Platform Book a SOC Assessment vulnerability-management Intel Hub
Is your security operations ready?
Get a free SOC assessment or see how AlertMonitor cuts through alert noise with automated triage.