logo

Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution

ID: d91ecb20-b96d-59d4-b257-c88a0284bc1f

STIX ID: report--d91ecb20-b96d-59d4-b257-c88a0284bc1f

Feed Name: GBHackers

Threat Score
78/100

Date Published: 2026-09-04

Date Updated: 2026-09-11

Author: Divya

...
...

A critical unauthenticated arbitrary file-upload vulnerability (CVE-2026-14894) affects Super Forms ≤ 6.3.313 and has been actively exploited since mid-July 2026; attackers can upload PHP backdoors (observed payload: Mushr00w_upl.php) via the super_submit_form AJAX action, enabling web shells, further malware staging, data exfiltration, and persistent site takeover. Administrators should immediately update Super Forms to 6.3.314, inspect writable webroots for unexpected PHP files (especially modified on/after July 8), and review web server logs for requests to /wp-admin/admin-ajax.php?action=super_submit_form and activity from the listed source IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.