Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total1
Critical1
High0
Medium0
Reset
Showing 1-1 of 1 records
Threat Entry Updated 2026-07-10

CVE-2026-14894 - Super Forms – Drag & Drop Form Builder Plugin

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce…

PLUGIN Super Forms – Drag & Drop Form Builder

CVE-2026-14894

CRITICAL CVSS 9.8 2026-07-10
Scroll to top