A critical vulnerability in Super Forms, a form-building plugin installed on an estimated 13,000 WordPress sites, has been under active attack for weeks. Wordfence has blocked over 250,000 exploit attempts targeting it.

What happened

The flaw, tracked as CVE-2026-14894, lets an unauthenticated attacker upload arbitrary files through the plugin’s data parameter, including PHP backdoors that hand them remote code execution on your server. Wordfence rates it 9.8 out of 10, its highest severity tier. It affects Super Forms version 6.3.313 and earlier.

The Super Forms developer shipped a patched version, 6.3.314, on July 8, 2026. Wordfence publicly disclosed the vulnerability the next day. Attackers started exploiting it on July 14, the same day Wordfence rolled out a firewall rule to block known attack attempts.

What to do

  1. Update Super Forms to version 6.3.314 or later from your WordPress dashboard now.
  2. If you’re on Wordfence Premium, Care, or Response, you’ve had a firewall rule blocking known exploit attempts since July 14. Free Wordfence users received the same protection on August 13.
  3. If your site has been running an outdated version of Super Forms for weeks, check your server for unfamiliar PHP files, especially in upload directories, since attackers have had almost two months to exploit this bug.

End of article