CVE-2026-14894Active Exploitation

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 14 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce requirement is trivially bypassed because the super_create_nonce nopriv AJAX action allows any unauthenticated visitor to mint a valid sf_nonce and session cookie in a single prior request, reducing exploitation to two unauthenticated HTTP requests.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-434

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 15 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 27 mentions across 10 observed days

What's happening

  • Active exploitation reported across 15 signals
  • Exploit tool or code specified in 2 signals
  • PoC mentioned or linked in 6 signals
  • Patch or workaround mentioned in 12 signals
  • Technical details provided in 21 signals
  • Disclosure: 5 classified signals
  • Peaked 6d ago at 14 mentions (2026-09-04); latest day: 1
  • 27 total mentions across 10 days

Deep dive

Activity timeline27 mentions / 10d
0471114Mentions · 2026-07-10: 4Mentions · 2026-08-08: 1Mentions · 2026-09-03: 1Mentions · 2026-09-04: 14Mentions · 2026-09-06: 1Mentions · 2026-09-08: 1Mentions · 2026-09-13: 1Mentions · 2026-09-21: 1Mentions · 2026-09-23: 2Mentions · 2026-09-24: 1PoC Mentioned / Linked · 2026-09-04: 3PoC Mentioned / Linked · 2026-09-21: 1PoC Mentioned / Linked · 2026-09-23: 1PoC Mentioned / Linked · 2026-09-24: 1Exploit Tool / Code · 2026-09-03: 1Exploit Tool / Code · 2026-09-23: 1Active Exploitation · 2026-09-03: 1Active Exploitation · 2026-09-04: 12Active Exploitation · 2026-09-06: 1Active Exploitation · 2026-09-08: 1Patch / Workaround · 2026-07-10: 3Patch / Workaround · 2026-09-03: 1Patch / Workaround · 2026-09-04: 6Patch / Workaround · 2026-09-06: 1Patch / Workaround · 2026-09-13: 1Technical Details · 2026-07-10: 4Technical Details · 2026-08-08: 1Technical Details · 2026-09-03: 1Technical Details · 2026-09-04: 12Technical Details · 2026-09-06: 1Technical Details · 2026-09-13: 1Technical Details · 2026-09-21: 107-1008-0809-0309-0409-0609-0809-1309-2109-2309-24
Signal classification6 categories
Active Exploitation
1451.9%
Disclosure
518.5%
Patch
414.8%
PoC
27.4%
Exploit
13.7%
General
13.7%
Referenced assets14 URLs
Classification over time
DateTotalLabels
2026-07-104
Disclosure2Patch2
2026-08-081
Disclosure1
2026-09-031
Active Exploitation1
2026-09-0414
Active Exploitation11Disclosure2Patch1
2026-09-061
Active Exploitation1
2026-09-081
Active Exploitation1
2026-09-131
Patch1
2026-09-211
PoC1
2026-09-232
Exploit1General1
2026-09-241
PoC1
Full discourse20 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-14894 - critical 🚨 WordPress Super Forms <= 6.3.313 - Arbitrary File Upload > Super Forms – Drag & Drop Form Builder WordPress plugin \u003C= 6.3.313 contains an a... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-14894 @pdnuclei #NucleiTemplates #cve

    Post summary

    A critical arbitrary file upload vulnerability in WordPress Super Forms plugin v6.3.313 or earlier has been disclosed, but no exploit or patch details are provided.

    01043502
    1.3K followersView on X
  • The CyberSec Guru@thecybersecguru
    Active Exploitation

    🚨 440,000+ exploit attempts. Two WordPress plugins. Full RCE. Attackers are actively targeting: 🔴 Super Forms — CVE-2026-14894 (9.8) 🔴 Elementor Pro — CVE-2026-32475 (9.0/9.8) The flaws allow unauthenticated attackers to upload malicious PHP files and execute code on vulnerable sites. Patch. Scan. Don't assume you're safe just because you updated. Full technical breakdown 👇 https://thecybersecguru.com/news/wordpress-super-forms-elementor-pro-rce-cve-2026-14894-cve-2026-32475/ #Infosec #WordPress

    Post summary

    Over 440,000 exploit attempts target two WordPress plugins via CVE-2026‑14894 and CVE-2026‑32475, enabling unauthenticated RCE through PHP file upload; attackers are active, and patching is urged.

    00052341
    1.6K followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2025-6325, CVE-2025-6327 CVE-2024-21413 CVE-2026-14894 CVE-2026-90817 CVE-2026-90817 ..🧵👇

    Post summary

    The post is a short threat digest that lists several CVEs and labels them as critical exploits disclosed today, but it provides no specific PoC, exploit tool, active exploitation, patch, or technical vulnerability details.

    1101055
    227 followersView on X
  • kokumօtօ@__kokumoto
    Active Exploitation

    13,000サイトが使用しているWordPressのSuper Formsプラグインの重大(Critical)な脆弱性が悪用されている。CVE-2026-14894はCVSSスコア9.8で、無認証でPHPファイルをアップロードできるもの。Wordfence社報告によると、7/14から攻撃あり。 https://securityonline.info/super-forms-cve-2026-14894-rce/

    Post summary

    The CVE-2026-14894 affects the Super Forms plugin, has a CVSS score of 9.8, and has been actively exploited since July 14, with reported PHP file upload capabilities.

    00021948
    7.8K followersView on X
  • Nxploited@Nxploited
    PoC

    CVE-2026-14894 | CVE-2026-32475 unauthenticated arbitrary file upload PoC: https://github.com/Nxploited/CVE-2026-14894 #CyberSecurity #InfoSec #0day #CVE #EthicalHacking #ExploitDev #WordPress

    Post summary

    The post discloses two CVEs (CVE-2026-14894, CVE-2026-32475) involving unauthenticated arbitrary file upload in WordPress and primarily shares a GitHub Proof-of-Concept (PoC) repository for CVE-2026-14894.

    00020253
    126 followersView on X
  • Caldura@Caldura7
    Active Exploitation

    CVE-2026-14894: Super Forms unauth upload (CVSS 9.8) under active exploit. Attackers drop PHP webshells. Wordfence blocked 250k+ attempts. Patch to 6.3.314+. #cybersecurity #infosec #WordPress #CVE #RCE https://t.co/GrCQULGaiD

    Post summary

    CVE-2026-14894 is actively exploited via unauthenticated file uploads, leading to PHP webshells. Wordfence detected over 250k attempts, and a patch (6.3.314+) is available.

    0001158
    60 followersView on X
  • PositiveSkeptic@PositiveSkeptik
    Patch

    Chrome just patched its 6th actively-exploited zero-day of 2026. Restart your browser today — Positive explains why, Skeptic explains why you probably won't. Today's desk: Google fixed a high-severity Chrome V8 flaw (CVE-2026-85046) already being exploited in the wild; over 440,000 attacks have hit WordPress sites through Elementor Pro and Super Forms plugin bugs, planting webshells; Thomson Reuters/West Publishing confirmed a breach of its C-Track court software touching 11 US states, the US Virgin Islands, and Ontario, where sealed records and SSNs "may have been exposed"; and OpenAI pledged $1B in AI credits to help hospitals, schools, water systems, and local governments defend against cyberattacks. Sources: @thehackernews @NVDgov @BleepingComputer @Reuters @OpenAI 🔗 Chrome 6th zero-day of 2026 (CVE-2026-85046, CVSS 8.8): Chrome Releases | NVD | The Hacker News | SecurityWeek 🔗 440,000+ WordPress plugin exploit attempts (Elementor Pro CVE-2026-32475, Super Forms CVE-2026-14894): The Hacker News | BleepingComputer 🔗 Thomson Reuters/West Publishing court software breach: Reuters | Supreme Court of Ohio | The Hacker News 🔗 OpenAI $1B "Daybreak for Frontline Defenders" pledge: OpenAI | The Register | Punchbowl News Spread the word — repost, share, like, and comment. #CyberSecurity #AINews #PositiveSkeptic #staypositive

    Post summary

    Chrome has released a patch for CVE‑2026‑85046, a high‑severity V8 flaw that is actively exploited; 440,000+ WordPress plugin attacks were reported, prompting users to update their browsers.

    10010100
    59 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-14894 (CVSS 9.8): Unauthenticated arbitrary file upload in the Super Forms WordPress plugin is actively exploited at scale, with 250,000+ blocked attempts and PHP webshells being dropped on vulnerable sites. - CVE-2026-14894 affects Super Forms <= 6.3.313. The submit_form() nopriv AJAX handler accepts a base64-encoded datauristring, decodes it, and writes it to disk using an attacker-controlled filename with zero file-type validation. A valid nonce is freely minted via the super_create_nonce nopriv endpoint, so the full exploit chain is just two unauthenticated HTTP POST requests to /wp-admin/admin-ajax.php. - The webshell observed in the wild is named Mushr00w_upl.php, a browser-based uploader used to stage further payloads. Exploitation began July 14, 2026, five days after disclosure, with a major spike August 18-25. Top offending IPs include 103.168.147[.]235 (106k+ requests) and 103.168.146[.]131 (82k+ requests). - For incident response: search the entire WordPress docroot for .php files created or modified on or after July 8, 2026. Check web server access logs for POST requests to /wp-admin/admin-ajax.php with action=super_submit_form. The filename Mushr00w_upl.php is a strong IOC but attackers vary filenames and can use path traversal to place shells outside the upload directory. Patch to Super Forms 6.3.314 immediately. #DFIR_Radar

    Post summary

    CVE‑2026‑14894 is a highly critical arbitrary file upload in Super Forms, actively exploited in the wild with thousands of attempts and webshell drops, and a patch is available.

    20000182
    1.9K followersView on X
  • ExploitGrid@exploitgrid
    PoC

    💀 CRITICAL Exploits Trending ├ CVE-2025-6325 / CVE-2025-6327 · PoC live ├ CVE-2024-21413 — "MonikerLink" · PoC live └ CVE-2026-14894 · CVE-2026-90817 · PoC live

    Post summary

    The post lists five CVEs and explicitly flags that Proof of Concept (PoC) code is live for each, making the availability of PoCs the primary takeaway.

    1000039
    308 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] CVE-2026-14894 [CRITICAL/PoC] CVE-2026-14894 🔗 https://exploitgrid.net/exploits/189a713a-b85b-4dc3-b7ce-9cd498a310bf

    Post summary

    The post announces CVE-2026-14894 as CRITICAL, explicitly tags it as an '[EXPLOIT]' and '[PoC]', and links to an exploit repository, though it reports no confirmed active exploitation or available patches.

    1000028
    227 followersView on X
  • Olivier Cloux F4ASJ@ocloux
    Patch

    🚨 Super Forms (#WordPress) : faille critique Uupload PHP arbitraire sans compte via un endpoint AJAX qui distribue son propre nonce. 250 000+ attaques bloquées (#Wordfence). 🔍Vu dans mes logs. 🩹Patcher ! https://www.cloux.net/securite/wordpress-securite-cve-2026-14894/ #Cybersécurité

    Post summary

    The tweet reports CVE-2026-14894 in the Super Forms WordPress plugin, detailing an arbitrary PHP upload vulnerability via an AJAX endpoint, notes 250K+ blocked attacks by Wordfence, and explicitly urges patching.

    00010114
    335 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Active Exploitation

    WordPressのフォーム プラグイン「Super Forms」の脆弱性 CVE-2026-14894が25万件超のサイバー攻撃への悪用を試行 https://rocket-boys.co.jp/security-measures-lab/wp-super-forms-cve-2026-14894-incident/ #セキュリティ対策Lab #security #securitynews #セキュリティ #脆弱性

    Post summary

    CVE-2026-14894 in the WordPress Super Forms plugin is being actively exploited, with more than 250,000 attack attempts reported.

    00010152
    636 followersView on X
  • CERT-PY@CERTpy
    Disclosure

    ⚠️ Vulnerabilidad en complemento de WordPress ❗ CVE-2026-14894 ➡️ Más info: https://www.cert.gov.py/vulnerabilidad-en-complemento-de-wordpress-12/ https://t.co/nEGLwfWRZi

    Post summary

    The text announces a new CVE-2026-14894 vulnerability affecting a WordPress plugin, directing readers to a CERT page for additional information.

    01000260
    6.7K followersView on X
  • Frontiera Tech@FrontieraTechIT
    Active Exploitation

    🛡️ CYBER BULLETIN | 2026/09/04 🚨 1. Chrome patches an actively exploited V8 zero-day Google shipped Chrome 152 to fix 12 bugs, including CVE-2026-85046, a type-confusion flaw in V8 already used in the wild. A crafted page can run code inside the sandbox. Update now — this is Google’s sixth exploited Chrome zero-day of 2026. 2. WordPress sites hit by mass RCE on Super Forms and Elementor Pro Wordfence has blocked 440,000+ attempts against CVE-2026-14894 and CVE-2026-32475. Both let unauthenticated attackers upload PHP and take over the site. Patch Super Forms to 6.3.314+ and Elementor Pro to 4.2.2+, then check uploads for webshells. 3. CISA adds seven KEVs — new SonicWall SMA1000 chain included CISA listed seven flaws under active attack, including SonicWall SMA1000 CVE-2026-83548 / CVE-2026-83549 (chained for unauth RCE), Sangoma Switchvox SQLi, and JFrog Artifactory auth bypass. Edge VPN boxes and software supply-chain tools are in the blast radius. #Cybersecurity #CISA #NIST

    Post summary

    The bulletin reports several actively exploited CVEs—ranging from a Chrome V8 zero‑day to WordPress plugin RCEs and CISA‑listed KEVs—and urges immediate patching to mitigate the ongoing attacks.

    1000077
    86 followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨Critical - Super Forms WordPress Plugin Unauthenticated File Upload to RCE (CVE-2026-14894) Super Forms' submit_form nopriv AJAX handler does no file-type validation and no capability check — its only barrier is a session nonce. That barrier is trivially bypassed: the super_create_nonce nopriv action lets any unauthenticated visitor mint a valid sf_nonce and session cookie in one prior request. So exploitation is just two unauthenticated HTTP requests - mint a nonce, then upload an executable file (e.g. a PHP web shell) - yielding remote code execution on the site. No auth, no user interaction (CVSS 9.8). 👉Update Super Forms beyond 6.3.313 to the patched release.

    Post summary

    Critical unauthenticated file upload in Super Forms WordPress plugin enables RCE; update to version 6.3.313 or newer to remediate.

    00010203
    246 followersView on X
  • Orizon@OrizonCyber
    Disclosure

    🚨 CVE-2026-14894 — CVSS 9.8/10 ██████████ The Super Forms – Drag &amp; Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/INIo3X7QcZ

    Post summary

    The tweet announces the critical CVE-2026-14894 affecting the Super Forms WordPress plugin, detailing its severity and type, and indicates that a patch is available.

    10000149
    65 followersView on X
  • PCMedicalist@PCMedicalist
    Active Exploitation

    PCMedicalist Signal · Sep 04 CVE-2026-14894--Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws: patch Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws immediately--RCE exposure. Full PCMedicalist · https://pcmedicalist.com/intel https://t.co/VAj1Zys2mV

    Post summary

    The tweet announces that CVE-2026-14894 is being actively exploited—over 440,000 attempts against Super Forms and Elementor Pro—highlighting an RCE flaw and urging users to apply a patch immediately.

    0000055
    153 followersView on X
  • protect_cyber_sec@AmirHossein_sec
    Disclosure

    برای پلاگین Super Forms در Wordpress آسیب پذیری با کد شناسایی CVE-2026-14894 از نوع RCE منتشر شده است، هکرها با استفاده از این آسیب پذیری می توانند فایل php به عنوان backdoor بر روی سایت آسیب پذیر بارگزاری نمایند و از طریق آن به صورت remote، کد اجرا نمایند. https://t.co/JkSLA2bAdh

    Post summary

    The tweet announces the release of CVE‑2026‑14894 as a remote code execution vulnerability in the WordPress Super Forms plugin, allowing attackers to upload PHP backdoors.

    0000089
    207 followersView on X
  • SecureChap@SecureChap
    Active Exploitation

    CVE-2026-14894 and CVE-2026-32475 attracted over 440,000 blocked exploit attempts. Wordfence logged more than 250,000 requests against the Super Forms flaw and 190,000 against Elementor Pro. CVE-2026-14894 in Super Forms before 6.3.314 accepts an unauthenticated POST to /wp-admin/admin-ajax.php?action=super_submit_form. The sf_upload_field parameter carries Base64 data:image/gif content followed by an attacker-chosen .php filename. CVE-2026-32475 in Elementor Pro before 4.2.2 needs one published page containing a Form widget with a File Upload field. The field is submitted as an array whose second element holds the .php payload; the file lands in /wp-content/uploads/elementor/forms/ under a random name. Activity against the first CVE started 2026-07-14 from IPs such as 103.168.147.235, 103.168.146.131, and 103.154.152.178, peaking above 40,000 requests on 2026-08-18. The second CVE saw traffic from 2026-08-19 onward from 185.196.220.85, 103.84.230.85, and 216.126.225.208. Both vectors write PHP directly with no authentication. WordPress sites that left either plugin unpatched stayed reachable for weeks after the fixes shipped.

    Post summary

    The post outlines extensive blocked exploitation attempts against two WordPress plugin CVEs, provides detailed exploitation mechanics, but offers no PoC, exploit code, or patch information.

    0000064
    172 followersView on X
  • Offensive Lab@OffensiveLab
    Active Exploitation

    Threat actors are exploiting two critical security flaws in #WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including executable PHP files, leading to remote code execution. (Fixed in version 6.3.314) CVE-2026-32475 (CVSS score: 9.0/9.8) - A vulnerability in Elementor Pro that allows unauthenticated attackers to upload files of any type, including executable PHP files, leading to remote code execution. (Fixed in version 4.2.2) As with arbitrary file upload vulnerabilities of this kind, an attacker can leverage them to write a PHP web shell to the site and execute arbitrary code, which can then be abused to create administrator accounts, exfiltrate data, or seize control of the entire WordPress site. Cybersecurity It's worth noting that details about CVE-2026-32475 were disclosed by Patchstack last month. Successful exploitation requires the target site to have at least one published Elementor page containing a Form widget with a File Upload field. In a pair of reports published this week, Wordfence said it has already blocked over 250,000 and 190,000 exploit attempts targeting CVE-2026-14894 and CVE-2026-32475, respectively

    Post summary

    Wordfence reports widespread exploitation of two high‑severity WordPress plugin CVEs, with over 250,000 attempts detected, and patches are available for both vulnerabilities.

    00000123
    250 followersView on X

Explore more