CVE-2026-14894
WebRehab Super Forms – Drag & Drop Form Builder
The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce requirement is trivially bypass...
- CVSS
- 9.8
- EPSS
- 0.74% 51.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.10