securityonline.info 9/4/2026, 4:35:44 AM · external

Super Forms Vulnerability Exploited in the Wild: 13,000 Sites Face 9.8 CVSS Remote Code Execution

Super Forms Vulnerability Exploited in the Wild: 13,000 Sites Face 9.8 CVSS Remote Code Execution
CyberSIXT Evidence Panel
Primary Source github.com
CISA KEV Not in KEV
Patch Patch Status Unknown

THE page outlines a critical alert about seven active vulnerabilities, particularly highlighting CVE-2026-14894—a serious flaw in the Super Forms plugin for WordPress that allows unauthenticated file uploads leading to remote code execution. This vulnerability received a CVSS score of 9.8, indicating its critical nature. Attackers exploit it by using a session nonce easily obtainable by unauthenticated users, allowing them to execute arbitrary PHP code.

Over 250,000 exploit attempts have been reported, and all versions up to 6.3.313 are affected. Users are urged to update to version 6.3.314 to mitigate the risk.

View Primary Source Via securityonline.info

Article by CyberSIXT