As cited
Copy frozen at (site build).
vulnerabilities
Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin
A critical unauthenticated arbitrary file upload vulnerability (CVE-2026-14894, CVSS 9.8) in the Super Forms WordPress plugin, affecting versions up to 6.3.313, enables attackers to upload PHP webshells and achieve remote code execution. The vulnerability was disclosed July 9, 2026, with a patch available July 8, 2026, and active exploitation began July 14, 2026. Wordfence firewall has blocked over 250,000 exploit attempts, with peak activity between August 18 and 25, 2026, and users are urged to update to version 6.3.314 immediately.
Why it matters: WordPress site administrators running Super Forms versions up to 6.3.313 face imminent risk of complete site compromise through unauthenticated exploitation that has already been weaponized at scale; immediate patching and review of access logs and filesystem for suspicious PHP files are required.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin
A critical unauthenticated arbitrary file upload vulnerability (CVE-2026-14894, CVSS 9.8) in the Super Forms WordPress plugin, affecting versions up to 6.3.313, enables attackers to upload PHP webshells and achieve remote code execution. The vulnerability was disclosed July 9, 2026, with a patch available July 8, 2026, and active exploitation began July 14, 2026. Wordfence firewall has blocked over 250,000 exploit attempts, with peak activity between August 18 and 25, 2026, and users are urged to update to version 6.3.314 immediately.
Why it matters: WordPress site administrators running Super Forms versions up to 6.3.313 face imminent risk of complete site compromise through unauthenticated exploitation that has already been weaponized at scale; immediate patching and review of access logs and filesystem for suspicious PHP files are required.
- Source published
- First seen by Cybersecurity Tracker