Super Forms WordPress Plugin Vulnerable to Arbitrary File Upload
The Super Forms – Drag & Drop Form Builder plugin for WordPress appears to be vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313. This vulnerability could allow unauthenticated attackers to upload executable files, potentially leading to remote code execution.
What happened
An early warning has been issued regarding a critical vulnerability in the Super Forms – Drag & Drop Form Builder plugin for WordPress. The vulnerability, tracked as CVE-2026-14894, is reportedly present in all versions up to and including 6.3.313. This flaw allows for Arbitrary File Upload due to missing file type validation and the absence of capability checks on the submit_form nopriv AJAX handler.
The vulnerability is under investigation, but initial reports indicate that unauthenticated attackers could exploit this by uploading executable files, which may lead to remote code execution. The exploitation appears to be facilitated by the trivial bypassing of the nonce requirement, which allows any unauthenticated visitor to mint a valid sf_nonce and session cookie in a single prior request.
Professional software engineers using this plugin are advised to assess their exposure by reviewing their current version and comparing it against the affected versions. It is recommended to upgrade to the latest version of the Super Forms – Drag & Drop Form Builder plugin as soon as it becomes available to mitigate this vulnerability. For more detailed information, primary sources should be consulted.
How 0Day mitigates this
super forms – drag & drop form builder is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.