Threat Advisory

Super Forms Flaw Lets Unauthenticated Users Upload PHP Files

Threat: Vulnerability
Targeted Region: Global
Targeted Sector: Technology & IT
Criticality: Critical
[subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-14894 (CVSS 9.8): A critical unauthenticated arbitrary file upload vulnerability exists in the WebRehab Super Forms – Drag & Drop Form Builder WordPress plugin. The flaw in the submit_form function allows unauthenticated attackers to bypass file-type validation and upload PHP files to the server using the data parameter. Because the vulnerable function is publicly accessible and the required nonce can also be obtained without authentication, exploitation can lead directly to remote code execution and complete WordPress site takeover.

RECOMMENDATION:

We recommend you to update Super Forms to version 6.3.314.[/subscribe_to_unlock_form]

EXECUTIVE SUMMARY:

CVE-2026-14894 (CVSS 9.8): A critical unauthenticated arbitrary file upload vulnerability exists in the WebRehab Super Forms – Drag & Drop Form Builder WordPress plugin. The flaw in the submit_form function allows unauthenticated attackers to bypass file-type validation and upload PHP files to the server using the data parameter. Because the vulnerable function is publicly accessible and the required nonce can also be obtained without authentication, exploitation can lead directly to remote code execution and complete WordPress site takeover.

RECOMMENDATION:

We recommend you to update Super Forms to version 6.3.314.[emaillocker id="1283"]

REFERENCES:

The following reports contain further technical details:

[/emaillocker]
crossmenu