Search
Find merged stories by title or summary.
Hackers Exploit Critical Super Forms WordPress Flaw to Upload Webshells and Execute Code
Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin to upload PHP webshells and potentially seize full control of vulnerable websites. Wordfence said its firewall has already blocked more than 250,000 exploitation attempts. The issue, tracked as CVE-2026-14894, affects Super Forms – Drag & Drop Form Builder versions 6. 3. 313 and earlier. The vulnerability carries a CVSS score of 9.8 and allows unauthenticated attackers to upload arbitrary files, including executable PHP code, without requiring a legitimate WordPress account. Critical Super Forms WordPress Flaw Super Forms, which has an estimated 13,000 active installations, supports file-upload fields in website forms.
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including
You've reached the end of current stories for this search.
