Attackers are actively exploiting CVE-2026-14894, a critical CVSS 9.8 unauthenticated arbitrary-file-upload vulnerability in the WordPress Super Forms – Drag & Drop Form Builder plugin through version 6.3.313. Insufficient file-type validation and a weak nonce mechanism in unauthenticated AJAX handlers let attackers obtain a valid nonce, upload executable PHP files, and potentially gain remote code execution and full control of affected sites. Roughly 13,000 active installations may be exposed.
Exploitation was observed beginning July 14 and surged between August 18 and 25, with Wordfence blocking more than 250,000 attempts. Attackers have deployed a PHP webshell named Mushr00w_upl.php. Administrators should immediately upgrade to Super Forms 6.3.314, released July 8, and investigate web roots and upload directories for unexpected PHP files and suspicious requests to the plugin's vulnerable AJAX endpoint.

See which actors are running it and whether you're in range.
7 events from the most recent confirmed update back to the earliest known activity.
The Wordfence firewall rule for CVE-2026-14894 was made available to free users.
Wordfence observed especially heavy exploitation activity targeting CVE-2026-14894. It ultimately reported blocking more than 250,000 attempts, including more than 106,000 requests from 103.168.147.235 and more than 82,000 from 103.168.146.131.
Wordfence deployed a firewall rule for Premium, Care, and Response users to protect against exploitation of CVE-2026-14894.
Wordfence telemetry indicated that attackers began targeting CVE-2026-14894, using the unauthenticated upload path to place PHP payloads and webshells on vulnerable WordPress sites.
The critical Super Forms vulnerability, CVE-2026-14894, was disclosed. The flaw permits unauthenticated attackers to obtain a nonce and upload executable PHP files through the plugin's AJAX submission functionality.
Version 6.3.314 of the Super Forms – Drag & Drop Form Builder WordPress plugin was released, remediating the critical unauthenticated arbitrary-file-upload vulnerability affecting version 6.3.313 and earlier.
Wordfence published a technical incident analysis documenting exploitation via the super_submit_form AJAX action, including Base64-encoded PHP payloads masquerading as GIF data and the Mushr00w_upl.php webshell filename.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. View all 10 in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
2 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcemalware.news
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.