CVE-2026-28167

WordPress Super Forms plugin <= 6.3.315 - Arbitrary File Download vulnerability

Unauthenticated Arbitrary File Download in Super Forms <= 6.3.315 versions.


We have discovered 957 live websites that are affected by CVE-2026-28167.

Run a Free Instant Scan




Affected Software

Product  Super Forms
Category Form Builders
Vulnerable Domains957 live websites (95% of Super Forms install base)
Vulnerable Versions
  • from 0 through 6.3.315
Vulnerable Versions Count72 versions ( 95% of all versions)


Common Weakness Enumeration

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')



Details

  • Published - Aug 24, 2026
  • Updated - Aug 24, 2026

Credits

  • VanTastic | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2026-28167
United States231 websites



Germany127 websites
GB42 websites
Netherlands37 websites
South Africa36 websites
Canada35 websites
France34 websites
Poland32 websites
Italy32 websites
Russia30 websites

Website Distribution by TLD

Number of websites using CVE-2026-28167
.com374 websites
.de83 websites
.org33 websites
.nl31 websites
.pl25 websites
.ru25 websites
.ca24 websites
.com.au23 websites
.it21 websites
.co.uk19 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-28167

Top websites that are affected by CVE-2026-28167. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
********.***.br Brazil**,***
*****.***.co Colombia***,***
*******.de Germany***,***
**.net United States***,***
****.org United States*,***,***
**********.***.mx Mexico*,***,***
******.com Czech Republic*,***,***
******.com Romania*,***,***
**********************.org United States*,***,***
*************.com Turkey*,***,***
See full domain list

FAQ

CVE-2026-28167 is Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in Super Forms
A total of 957 websites have been identified as vulnerable to CVE-2026-28167, based on global website indexing conducted by WebTechSurvey.
The Super Forms is affected by the CVE-2026-28167 vulnerability.
Super Forms versions up to and including 6.3.315 are vulnerable to CVE-2026-28167.