CVE-2026-14894P1CRITICALCVSS 9.8ExploitedPoC≤ 6.3.3132026-07-10
CVE-2026-14894 [CRITICAL] CWE-434 CVE-2026-14894: The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Uplo
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely o
nvd