Super Forms ≤6.3.313 unauth arbitrary file upload RCE (CVE-2026-14894); mass exploitation
Wordfence (via The Hacker News, 4 September 2026) reports active exploitation of CVE-2026-14894 in the WordPress plugin Super Forms – Drag & Drop Form Builder. NVD/Wordfence describe missing file-type validation on the unauthenticated submit_form AJAX handler (session nonce obtainable via a separate nopriv endpoint), allowing unauthenticated arbitrary file upload and remote code execution. Wordfence CVSS 3.1 is 9.8 Critical. Affected: all versions through 6.3.313; fixed in 6.3.314. Wordfence says it blocked over 250,000 exploit attempts against this CVE (plus ~190,000 against Elementor Pro CVE-2026-32475 in the same reporting wave; Elementor stays on its own desk card). Observed Super Forms attacks POST to /wp-admin/admin-ajax.php with action=super_submit_form and a Base64 PHP web shell disguised as a data:image/gif payload (e.g. Mushr00w_upl.php); activity began 14 July 2026 and peaked above 40,000 requests on 18 August 2026. Upgrade Super Forms to 6.3.314+; hunt unexpected .php under uploads; keep WAF rules current. Distinct from cve-2026-32475 (Elementor Pro).
- Product
- Super Forms – Drag & Drop Form Builder (WordPress)
- Versions
- Affected ≤6.3.313; fixed in 6.3.314
- CVSS
- (CVSS 3.1 Wordfence/NVD)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Super Forms 6.3.314 or later; audit uploads for unexpected PHP; review admin-ajax.php logs for super_submit_form
Primary: NVD CVE-2026-14894 (Wordfence CNA; CVSS 9.8) · Vendor: Wordfence threat-intel (CVE-2026-14894) · CVE: CVE-2026-14894, CVE-2026-32475 · The Hacker News (4 Sep 2026; Wordfence telemetry)
