Teisoft Exposure Platform
Sign in
criticalCVE-2026-14894CVSS 9.8

WordPress Super Forms <= 6.3.313 - Arbitrary File Upload

Super Forms – Drag & Drop Form Builder WordPress plugin \u003C= 6.3.313 contains an arbitrary file upload vulnerability caused by missing file type validation and lack of capability checks in submit_form nopriv AJAX handler, letting unauthenticated attackers upload executable files and achieve remote code execution, exploit requires no authentication due to nonce bypass.

Enter a domain you own and we will test it right now — and, while we are there, report anything else it exposes publicly. No account, no agent to install.

No signup. Takes about a minute. We request pages your server already serves publicly — nothing is written, exploited or brute-forced.

How to fix it

Update to the latest version of Super Forms – Drag & Drop Form Builder plugin.

What this check actually does

  • Fingerprints the host — server, technologies, certificate and response headers.
  • Runs the WordPress Super Forms <= 6.3.313 - Arbitrary File Upload detection against it.
  • Runs a short pass for common misconfigurations, exposed files and TLS problems.
  • Cross-references the detected versions against published CVEs.

Everything is read-only: requests for pages your server already serves to anyone. Nothing is written, exploited or brute-forced, and no traffic is generated beyond a normal crawl.

Tags

cvecve2026wordpresswp-pluginwpfile-uploadrceintrusivevkev