← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 4, 2026 · 10:01via CyberPress

Hackers Exploit Critical Super Forms WordPress Flaw to Upload Webshells and Execute Code

Brief

Threat actors are actively exploiting a critical vulnerability in the Super Forms WordPress plugin to upload PHP webshells and potentially seize full control of vulnerable websites. Wordfence said its firewall has already blocked more than 250,000 exploitation attempts.

The issue, tracked as CVE-2026-14894, affects Super Forms – Drag & Drop Form Builder versions 6.

  • 313 and earlier.

The vulnerability carries a CVSS score of 9.8 and allows unauthenticated attackers to upload arbitrary files, including executable PHP code, without requiring a legitimate WordPress account.

Critical Super Forms WordPress Flaw

Super Forms, which has an estimated 13,000 active installations, supports file-upload fields in website forms.

Read more on CyberPress