HomeIntelligenceBrief
VULNERABILITY BRIEF 🔴 Critical Vulnerability

Critical File‑Upload Validation Flaw (CVE‑2026‑14894) Sparks 440k Exploit Attempts on WordPress Super Forms Plugin

A missing file‑type validation bug in the Super Forms WordPress plugin (CVE‑2026‑14894, CVSS 9.8) is being actively exploited, with over 440 000 attempts observed. The issue underscores the need for continuous third‑party component monitoring and auditable remediation to satisfy compliance and trust requirements.

Verisq™ Intelligence · 📅 September 04, 2026 · 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
Actions
4 recommended
📰
Source
thehackernews.com

Critical File‑Upload Validation Flaw in Super Forms Plugin (CVE‑2026‑14894) Fuels Massive Exploit Campaign

What It Is — A missing file‑type validation bug in the Super Forms – Drag & Drop Form Builder for WordPress allows unauthenticated attackers to upload arbitrary files, leading to remote code execution. The flaw is tracked as CVE‑2026‑14894 with a CVSS 9.8 rating.

Exploitability — Threat actors have launched more than 440 000 exploit attempts in the wild; public PoC scripts are circulating, confirming active exploitation.

Affected Products — Super Forms plugin (all versions prior to the vendor’s emergency patch) and Elementor Pro (related RCE issue disclosed alongside Super Forms).

Why It Matters for Trust & Control Assurance

  • Continuous monitoring of third‑party components is essential; the volume of attempts shows that unmanaged plugins become a rapid attack surface.
  • Demonstrable evidence of timely patching and configuration hardening satisfies auditors looking for a defensible supply‑chain posture.
  • Logging of file‑upload activity and anomaly detection provide the audit trail needed to prove due‑diligence during a security review.

Recommended Actions

  1. Apply the vendor‑released patches for Super Forms and Elementor Pro immediately.
  2. Enforce strict file‑type allow‑lists at the web‑server and application layers; block execution of uploaded files.
  3. Deploy a software‑composition analysis (SCA) tool to inventory WordPress plugins and receive real‑time vulnerability alerts.
  4. Enable detailed upload logging and integrate with a SIEM for anomaly detection.
  5. Review and harden your WordPress hardening checklist (disable unused plugins, enforce least‑privilege for plugin accounts).

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html

This Verisq Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Vulnerability exposure

Is this CVE in your supply chain?

Verisq matches published vulnerabilities against the software your vendors run, so you know which relationships this touches before the next review.

See vendor exposure →