WordPress Super Forms <= 6.3.313 - Arbitrary File Upload
Super Forms – Drag & Drop Form Builder WordPress plugin \u003C= 6.3.313 contains an arbitrary file upload vulnerability caused by missing file type validation and lack of capability checks in submit_form nopriv AJAX handler, letting unauthenticated attackers upload executable files and achieve remote code execution, exploit requires no authentication due to nonce bypass.
Enter a domain you own and we will test it right now — and, while we are there, report anything else it exposes publicly. No account, no agent to install.
How to fix it
Update to the latest version of Super Forms – Drag & Drop Form Builder plugin.
What this check actually does
- Fingerprints the host — server, technologies, certificate and response headers.
- Runs the WordPress Super Forms <= 6.3.313 - Arbitrary File Upload detection against it.
- Runs a short pass for common misconfigurations, exposed files and TLS problems.
- Cross-references the detected versions against published CVEs.
Everything is read-only: requests for pages your server already serves to anyone. Nothing is written, exploited or brute-forced, and no traffic is generated beyond a normal crawl.