CVE-2026-14894 – Super Forms – Drag & Drop Form Builder

CVSS 9.8 CRITICAL Zero Day – Immediate Deployment

“An unauthenticated file upload flaw can turn a public WordPress form into a path for full server compromise.”

WebRehab patched a critical arbitrary file upload vulnerability affecting Super Forms – Drag & Drop Form Builder through version 6.3.313. CVE-2026-14894 allows an unauthenticated attacker to obtain a valid nonce, upload potentially executable files, and achieve remote code execution. The CVSS score is 9.8, which is Critical severity.

Public proof-of-concept material and real-world exploitation have been reported. The issue is fixed in version 6.3.314.

Key Details

Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
CWE Classification
CWE-434
Patch this CVE on all your endpoints in under 5 minutes. First 200 endpoints are free forever, scale as needed.