CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 5808

As cited

Copy frozen at (site build).

vulnerabilities

Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin

A critical unauthenticated arbitrary file upload vulnerability (CVE-2026-14894, CVSS 9.8) in the Super Forms WordPress plugin, affecting versions up to 6.3.313, enables attackers to upload PHP webshells and achieve remote code execution. The vulnerability was disclosed July 9, 2026, with a patch available July 8, 2026, and active exploitation began July 14, 2026. Wordfence firewall has blocked over 250,000 exploit attempts, with peak activity between August 18 and 25, 2026, and users are urged to update to version 6.3.314 immediately.

Why it matters: WordPress site administrators running Super Forms versions up to 6.3.313 face imminent risk of complete site compromise through unauthenticated exploitation that has already been weaponized at scale; immediate patching and review of access logs and filesystem for suspicious PHP files are required.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin

A critical unauthenticated arbitrary file upload vulnerability (CVE-2026-14894, CVSS 9.8) in the Super Forms WordPress plugin, affecting versions up to 6.3.313, enables attackers to upload PHP webshells and achieve remote code execution. The vulnerability was disclosed July 9, 2026, with a patch available July 8, 2026, and active exploitation began July 14, 2026. Wordfence firewall has blocked over 250,000 exploit attempts, with peak activity between August 18 and 25, 2026, and users are urged to update to version 6.3.314 immediately.

Why it matters: WordPress site administrators running Super Forms versions up to 6.3.313 face imminent risk of complete site compromise through unauthenticated exploitation that has already been weaponized at scale; immediate patching and review of access logs and filesystem for suspicious PHP files are required.

VendorsWordPress
Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary