CVE-2026-14894
Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
Description
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce requirement is trivially bypassed because the super_create_nonce nopriv AJAX action allows any unauthenticated visitor to mint a valid sf_nonce and session cookie in a single prior request, reducing exploitation to two unauthenticated HTTP requests.
In plain language
AI Act nowSuper Forms – Drag & Drop Form Builder (up to 6.3.313) has a flaw that lets an unauthenticated person upload files to your WordPress site, which can lead to a full site takeover—this is serious enough that you should act now.
CVE-2026-14894 is an unauthenticated arbitrary file upload in Super Forms – Drag & Drop Form Builder (submit_form nopriv AJAX handler), where missing file-type checks and no permission check allow attackers to upload attacker-controlled files; exploitation is facilitated by an unauthenticated nonce/session minting flow.
What to do now
- Check whether you use “Super Forms – Drag & Drop Form Builder” in WordPress and confirm the plugin version is 6.3.313 or lower.
- If you are on 6.3.313 or lower, remove the plugin or disable the form submission feature immediately until you can get a safe version.
- Contact your WordPress/plugin vendor or IT support to obtain the patched version (a fixed upgrade version was not identified in the available patch information).
- If you cannot update right away, restrict access to WordPress admin endpoints and any publicly reachable form submission/upload paths using your web server/WAF, and monitor for new or unexpected uploaded files.
- Assume active probing is happening and review your site for signs of compromise (recent file changes, new admin users, suspicious files in upload folders).
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
3 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-14894 and every CVE in our database. Create a free account — no credit card required.
Create Free Account