Key Facts

SecurityWeek reports that attackers are exploiting CVE-2026-14894, a critical vulnerability in the WordPress Super Forms plugin.

Technical Details

The reported flaw permits unauthenticated arbitrary file uploads. SecurityWeek says exploitation can upload and execute PHP webshells, which can lead to complete control of an affected site.

Impact & Mitigation

Update Super Forms to version 6.3.314 as advised in the report. Review sites using the plugin for unexpected uploaded files, webshells, administrator accounts, and suspicious processes or outbound connections.

Sources

By Allan