CVE Tools

CVE-2026-14894

Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)

Published: Jul 10, 2026Updated: Jul 10, 2026 Sources: CVE List NVDCWE-434

Description

The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce requirement is trivially bypassed because the super_create_nonce nopriv AJAX action allows any unauthenticated visitor to mint a valid sf_nonce and session cookie in a single prior request, reducing exploitation to two unauthenticated HTTP requests.

In plain language

AI Act now

Super Forms – Drag & Drop Form Builder (up to 6.3.313) has a flaw that lets an unauthenticated person upload files to your WordPress site, which can lead to a full site takeover—this is serious enough that you should act now.

Executive summary

CVE-2026-14894 is an unauthenticated arbitrary file upload in Super Forms – Drag & Drop Form Builder (submit_form nopriv AJAX handler), where missing file-type checks and no permission check allow attackers to upload attacker-controlled files; exploitation is facilitated by an unauthenticated nonce/session minting flow.

If affected, business impact
Full website takeoverMalware or backdoor installationCustomer data theftSite disruption or downtime

What to do now

  1. Check whether you use “Super Forms – Drag & Drop Form Builder” in WordPress and confirm the plugin version is 6.3.313 or lower.
  2. If you are on 6.3.313 or lower, remove the plugin or disable the form submission feature immediately until you can get a safe version.
  3. Contact your WordPress/plugin vendor or IT support to obtain the patched version (a fixed upgrade version was not identified in the available patch information).
  4. If you cannot update right away, restrict access to WordPress admin endpoints and any publicly reachable form submission/upload paths using your web server/WAF, and monitor for new or unexpected uploaded files.
  5. Assume active probing is happening and review your site for signs of compromise (recent file changes, new admin users, suspicious files in upload folders).
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

Exploitability

No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

3 techniques
Command and Control
Initial Access
Persistence
View detailed technique mapping

References

1

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-14894 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows