Vendor
high
advisory
Arbitrary Directory Deletion in Super Forms WordPress Plugin
1 TTP 1 CVEUnauthenticated attackers can achieve arbitrary recursive directory deletion in Super Forms versions 6.3.316 and earlier by exploiting improper path validation in the submit_form function.
Super Forms – Drag & Drop Form Builder
wordpress
vulnerability
remote-deletion
web-application
1t
1c
critical
advisory
WordPress Super Forms Plugin Arbitrary File Upload (CVE-2026-14894)
1 rule 2 TTPs 1 CVE 11 IOCsAn unauthenticated arbitrary file upload vulnerability (CVE-2026-14894) exists in the Super Forms - Drag & Drop Form Builder plugin for WordPress, affecting all versions up to and including 6.3.313, allowing unauthenticated attackers to upload executable files via the `submit_form` AJAX handler, leading to remote code execution after trivial nonce bypass.
PoC
Super Forms – Drag & Drop Form Builder <= 6.3.313 +1
wordpress
plugin
arbitrary-file-upload
rce
web-exploit
1r
2t
1c
11i
updated