Skip to content
COOEY

EXPOSURES › CVE-2026-14894

CVE-2026-14894

CRITICAL
DETAIL
SourceNVD · cve Published2026-07-10 CVSS9.8 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-14894 ↗
⚡ RCE SHAME 45/100 rceexploited-in-wildunpatched

A WordPress plugin allows unauthenticated attackers to execute arbitrary code via file upload.

CVE-2026-14894 enables remote code execution in the Super Forms plugin by bypassing nonce validation and lacking file type checks, allowing unauthenticated attackers to upload and execute files. DIB organizations using WordPress for sensitive systems face critical exposure to RCE without requiring user credentials, necessitating immediate patching and audit of all WordPress plugin inventories.

Shame score — A critical RCE vulnerability in a widely used WordPress plugin that allows unauthenticated exploitation via file upload.

▸ RECOMMENDED ACTION  Remote code execution — patch the affected products on priority.

DESCRIPTION

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce requirement is trivially bypassed because the super_create_nonce nopriv AJAX action allows any unauthenticated visitor to mint a valid sf_nonce and session cookie in a single prior request, reducing exploitation to two unauthenticated HTTP requests.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.