Summary
CVE-2026-14894 is a critical unauthenticated arbitrary file upload vulnerability in the Super Forms – Drag & Drop Form Builder WordPress plugin by WebRehab, affecting all versions up to and including 6.3.313. Due to missing file type validation and the complete absence of any capability check on a public-facing AJAX endpoint, unauthenticated attackers can upload executable files and achieve remote code execution (RCE) on the host server. The vulnerability carries a CVSS v3.1 base score of 9.8 (Critical), and a patch was released in version 6.3.314 on July 7, 2026.
Technical details
- Root cause: The
submit_formnopriv AJAX handler performs no file type validation and no capability check, allowing arbitrary files — including executable PHP scripts — to be written to the server via the form submission flow. - Nonce bypass: The handler’s only nominal access control is a session nonce (
sf_nonce). A separate publicly accessible nopriv AJAX action,super_create_nonce, allows any unauthenticated visitor to mint a valid nonce and session cookie in a single HTTP request, fully negating this barrier. - Attack vector: Entirely network-based with no authentication required. Exploitation is reduced to exactly two unauthenticated HTTP requests: one to obtain a valid nonce via
super_create_nonce, and one to upload a malicious file viasubmit_form. - Impact: Successful exploitation results in remote code execution on the host server, with full compromise of confidentiality, integrity, and availability of the affected WordPress installation.
Affected software
- Super Forms – Drag & Drop Form Builder (WordPress plugin by WebRehab) — all versions up to and including 6.3.313
Severity
- CVSS v3.1 Base Score: 9.8 (Critical)
- Vector String:
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CWE: CWE-434 – Unrestricted Upload of File with Dangerous Type
Mitigation and recommended actions
- Immediate action: Update the Super Forms plugin to version 6.3.314 or later. The patch implements server-side file type verification (including magic-byte validation), filename sanitization, path containment via
realpath()checks, and stricter gating of file write operations within the form submission handler. - If immediate patching is not feasible: Disable the Super Forms plugin until the update can be applied. As an additional network-level mitigation, restrict unauthenticated access to the WordPress AJAX endpoint (
/wp-admin/admin-ajax.php) via WAF rules or perimeter controls to block exploitation of thesubmit_formandsuper_create_noncenopriv actions.
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

