Serious Vulnerability in WordPress Super Forms Under Active Exploitation

Try Our Free Tools!
Master the web with Free Tools that work as hard as you do. From Text Analysis to Website Management, we empower your digital journey with expert guidance and free, powerful tools.

Add Techlomedia as a Preferred Source on Google

A significant vulnerability has been detected in the widely utilized Super Forms – Drag & Drop Form Builder plugin for WordPress, which is presently being actively exploited by malicious actors.

This flaw permits unauthenticated attackers to upload arbitrary files to a compromised website, including executable PHP files that could enable full administrative control over the site.

As reported by Wordfence, the vulnerability impacts Super Forms versions 6.3.313 and earlier. It has been designated with the identifier CVE-2026-14894 and has a CVSS score of 9.8, categorizing it as a critical security risk.

The developer rectified the vulnerability with the release of version 6.3.314 on July 8, 2026, with Wordfence making the issue public just a day later on July 9.

This situation is alarming, particularly because attackers did not delay in their exploits following the disclosure of the vulnerability.

Wordfence reported the commencement of infiltration attempts as early as July 14, coinciding with the launch of its firewall rule to mitigate the issue.

Since then, the firewall has obstructed over 250,000 exploit attempts targeting the Super Forms vulnerability.

Moreover, Wordfence has documented a marked escalation in attacks between August 18 and August 25.

With an estimated 13,000 active installations, a considerable number of WordPress sites could potentially remain vulnerable if administrators have not undertaken the necessary updates.

The vulnerability resides in the plugin’s submit_form() function, responsible for managing form submissions and is accessible to any unauthenticated visitors.

Wordfence elucidates that the vulnerable code processes a datauristring value, decoding Base64 data under the control of the attacker before writing it to the server.

Additionally, it employs an attacker-specified filename without sufficient validation of the file type or extension. Consequently, this flaw allows an assailant to upload a file bearing a .php extension in place of a valid image or document.

This vulnerability is particularly insidious because the requisite security nonce can be acquired by an unauthenticated visitor via an alternate AJAX endpoint. Wordfence states that the exploitation can be distilled into merely two unauthenticated HTTP requests.

With this access, an attacker could upload a PHP webshell, execute arbitrary code on the server, establish administrator accounts, introduce additional malware, siphon off sensitive data, or otherwise compromise the WordPress installation.

In its investigation of the attacks, Wordfence identified the use of a PHP-based file uploader labeled Mushr00w_upl.php.

This filename has connections to a hacker organization that recently exploited another flaw to deface a Malaysian government website.

However, it is crucial to note that this association does not definitively implicate the group in these attacks.

Wordfence reports that its firewall has effectively blocked over 250,000 unauthorized requests aiming to exploit CVE-2026-14894.

The most prevalent IP addresses implicated in these attacks, as identified by Wordfence, include:

  • 103.168.147.235 with over 106,000 blocked requests
  • 103.168.146.131 with more than 82,000
  • 103.154.152.178 with upwards of 5,000
  • 103.170.97.7 with an excess of 3,400
  • 182.10.130.51 with above 3,000

Furthermore, other identified addresses listed by Wordfence also generated thousands of blocked requests.

If you are utilizing Super Forms on a WordPress website, it is imperative to upgrade to version 6.3.314 or later without delay.

Wordfence notes that Premium, Care, and Response customers received a firewall rule on July 14. Conversely, users of the free version of the Wordfence plugin received similar protection 30 days later, on August 13.

However, it is paramount to understand that a firewall rule is not a substitute for updating the vulnerable plugin.

Immediate action to update Super Forms is strongly recommended, even if your site appears safeguarded by Wordfence.

Website administrators should meticulously examine their sites for indicators of compromise, particularly if they were operating a susceptible version post-July 8.

Wordfence advises checking for unexpected or recently altered PHP files and any unusual files created since July 8.

Notably, Mushr00w_upl.php is one particular filename associated with these attacks, though attackers may employ various alternative names.

Additionally, it is advisable to scrutinize web server logs for requests made to:

/wp-admin/admin-ajax.php

with the action parameter designated as:

super_submit_form

Should you uncover signs of a successful breach, Wordfence recommends that you remove any unknown administrator accounts and suspicious files, while also investigating the site for additional backdoors.

A magnifying glass enlarges the word INVESTIGATING written in a notebook on a desk with books, papers, and a map.

The absence of these specific indicators does not necessarily imply that a site has not been compromised.

Source link: Techlomedia.in.

Disclosure: This article is for general information only and is based on publicly available sources. We aim for accuracy but can't guarantee it. The views expressed are the author's and may not reflect those of the publication. Some content was created with help from AI and reviewed by a human for clarity and accuracy. We value transparency and encourage readers to verify important details. This article may include affiliate links. If you buy something through them, we may earn a small commission — at no extra cost to you. All information is carefully selected and reviewed to ensure it's helpful and trustworthy.

Reported By

Souvik Banerjee

I’m Souvik Banerjee from Kolkata, India. As a Marketing Manager at RS Web Solutions (RSWEBSOLS), I specialize in digital marketing, SEO, programming, web development, and eCommerce strategies. I also write tutorials and tech articles that help professionals better understand web technologies.
Share the Love
Related News Worth Reading