Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution
ID: d91ecb20-b96d-59d4-b257-c88a0284bc1f
STIX ID: report--d91ecb20-b96d-59d4-b257-c88a0284bc1f
Feed Name: GBHackers
A critical unauthenticated arbitrary file-upload vulnerability (CVE-2026-14894) affects Super Forms ≤ 6.3.313 and has been actively exploited since mid-July 2026; attackers can upload PHP backdoors (observed payload: Mushr00w_upl.php) via the super_submit_form AJAX action, enabling web shells, further malware staging, data exfiltration, and persistent site takeover. Administrators should immediately update Super Forms to 6.3.314, inspect writable webroots for unexpected PHP files (especially modified on/after July 8), and review web server logs for requests to /wp-admin/admin-ajax.php?action=super_submit_form and activity from the listed source IPs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
