CVE-2026-14894 – Super Forms – Drag & Drop Form Builder
CVSS 9.8
CRITICAL
Zero Day – Immediate Deployment
“An unauthenticated file upload flaw can turn a public WordPress form into a path for full server compromise.”
WebRehab patched a critical arbitrary file upload vulnerability affecting Super Forms – Drag & Drop Form Builder through version 6.3.313. CVE-2026-14894 allows an unauthenticated attacker to obtain a valid nonce, upload potentially executable files, and achieve remote code execution. The CVSS score is 9.8, which is Critical severity.
Public proof-of-concept material and real-world exploitation have been reported. The issue is fixed in version 6.3.314.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-434
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.