Search

Find a vulnerability

Search criteria

    5 vulnerabilities found for Super Forms – Drag & Drop Form Builder by WebRehab

    CVE-2026-15896 (GCVE-0-2026-15896)

    Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
    VLAI
    Title
    Super Forms <= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via 'sfgtfi' URL Path Parameter
    Summary
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional 'file_upload_auth' setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin's file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form.
    CWE
    • CWE-26 - Path Traversal: '/dir/../filename'
    Impacted products
    Vendor Product Version
    WebRehab Super Forms – Drag & Drop Form Builder Affected: 0 , ≤ 6.3.316 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Super Forms \u2013 Drag \u0026 Drop Form Builder",
              "vendor": "WebRehab",
              "versions": [
                {
                  "lessThanOrEqual": "6.3.316",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "afei"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Super Forms \u2013 Drag \u0026 Drop Form Builder plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 6.3.316 via the parse_request function. This makes it possible for unauthenticated attackers to read the contents of arbitrary files on the server, which can contain sensitive information. The optional \u0027file_upload_auth\u0027 setting defaults to empty, meaning no authentication is required in the default configuration; enabling this setting mitigates unauthenticated exploitation but does not remediate the path traversal itself. Exploitation on Linux requires a real 13-digit timestamp directory to exist, whereas on Windows the traversal works with any hardcoded 13-digit prefix. However, the plugin\u0027s file upload response returns the name of the created directory, which means the vulnerability is exploitable as long as file upload is enabled on the form."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.1,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-26",
                  "description": "CWE-26 Path Traversal: \u0027/dir/../filename\u0027",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T05:30:18.601Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/dc3df045-1020-403f-8e10-a1b75261b769?source=cve"
            },
            {
              "url": "https://github.com/RensTillmann/super-forms/pull/205"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-07-15T18:14:05.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-01T16:32:09.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Super Forms \u003c= 6.3.316 - Unauthenticated Path Traversal to Arbitrary File Read via \u0027sfgtfi\u0027 URL Path Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-15896",
        "datePublished": "2026-10-02T05:30:18.601Z",
        "dateReserved": "2026-07-15T17:58:41.955Z",
        "dateUpdated": "2026-10-02T05:30:18.601Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-15897 (GCVE-0-2026-15897)

    Vulnerability from cvelistv5 – Published: 2026-10-02 05:30 – Updated: 2026-10-02 05:30
    VLAI
    Title
    Super Forms – Drag & Drop Form Builder <= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via 'user_id' Parameter in Register & Login
    Summary
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function, in its register_login_action='update' flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Because the super_save_form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register_login_action='update' with register_login_user_id_update='true') and then submit it with user_id set to an administrator's ID along with a new user_pass/user_email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts — including administrators — resulting in account takeover and full site compromise.
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    WebRehab Super Forms – Drag & Drop Form Builder Affected: 0 , ≤ 6.3.316 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Super Forms \u2013 Drag \u0026 Drop Form Builder",
              "vendor": "WebRehab",
              "versions": [
                {
                  "lessThanOrEqual": "6.3.316",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "d.v4n_s3c"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Super Forms \u2013 Drag \u0026 Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register \u0026 Login add-on\u0027s before_email_success_msg() function, in its register_login_action=\u0027update\u0027 flow, trusting an attacker-supplied user_id value and passing it to wp_update_user() without any ownership or capability check. Because the super_save_form AJAX action also enforces no capability check, any authenticated user with Subscriber-level access and above can create the required malicious form (register_login_action=\u0027update\u0027 with register_login_user_id_update=\u0027true\u0027) and then submit it with user_id set to an administrator\u0027s ID along with a new user_pass/user_email. This makes it possible for authenticated attackers with Subscriber-level access and above to overwrite the credentials of arbitrary existing accounts \u2014 including administrators \u2014 resulting in account takeover and full site compromise."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.8,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-02T05:30:17.190Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/94297481-9ebb-42cb-9362-be8bc52b126f?source=cve"
            },
            {
              "url": "https://github.com/RensTillmann/super-forms/pull/205"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-07-15T18:52:23.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-10-01T16:34:31.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Super Forms \u2013 Drag \u0026 Drop Form Builder \u003c= 6.3.316 - Authenticated (Subscriber+) Privilege Escalation via \u0027user_id\u0027 Parameter in Register \u0026 Login"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-15897",
        "datePublished": "2026-10-02T05:30:17.190Z",
        "dateReserved": "2026-07-15T18:15:21.788Z",
        "dateUpdated": "2026-10-02T05:30:17.190Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-15983 (GCVE-0-2026-15983)

    Vulnerability from cvelistv5 – Published: 2026-10-01 08:28 – Updated: 2026-10-01 08:28
    VLAI
    Title
    Super Forms <= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via 'subdir' / 'path' Parameter
    Summary
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check — allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting — combined with the `super_submit_form` handler's `submit_form` function passing the attacker-controlled `files[].subdir` value from `$_POST['data']` directly into `SUPER_Common::delete_dir()` without sanitization, and a trivially bypassed `ABSPATH` guard that a `subdir` value of `wp-config.php` defeats because `dirname(realpath(ABSPATH . $subdir))` resolves to the WordPress root while the naive `ABSPATH !== $dir` string check fails to match due to a trailing-slash mismatch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recursively delete arbitrary files and directories on the server, up to and including the entire WordPress installation, resulting in full site takedown and potential remote code execution if critical files such as `wp-config.php` are removed and the site is subsequently re-installed by another party.
    CWE
    • CWE-73 - External Control of File Name or Path
    Impacted products
    Vendor Product Version
    WebRehab Super Forms – Drag & Drop Form Builder Affected: 0 , ≤ 6.3.316 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Super Forms \u2013 Drag \u0026 Drop Form Builder",
              "vendor": "WebRehab",
              "versions": [
                {
                  "lessThanOrEqual": "6.3.316",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "d.v4n_s3c"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Super Forms \u2013 Drag \u0026 Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File/Directory Deletion in all versions up to, and including, 6.3.316. This is due to the `super_save_form` AJAX handler performing no capability check \u2014 allowing Subscriber-level authenticated users to create or modify Super Forms and enable the `file_upload_submission_delete` setting \u2014 combined with the `super_submit_form` handler\u0027s `submit_form` function passing the attacker-controlled `files[].subdir` value from `$_POST[\u0027data\u0027]` directly into `SUPER_Common::delete_dir()` without sanitization, and a trivially bypassed `ABSPATH` guard that a `subdir` value of `wp-config.php` defeats because `dirname(realpath(ABSPATH . $subdir))` resolves to the WordPress root while the naive `ABSPATH !== $dir` string check fails to match due to a trailing-slash mismatch. This makes it possible for authenticated attackers, with Subscriber-level access and above, to recursively delete arbitrary files and directories on the server, up to and including the entire WordPress installation, resulting in full site takedown and potential remote code execution if critical files such as `wp-config.php` are removed and the site is subsequently re-installed by another party."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 8.1,
                "baseSeverity": "HIGH",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-73",
                  "description": "CWE-73 External Control of File Name or Path",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T08:28:41.509Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/25704473-1200-49df-aa16-9a9558bb4844?source=cve"
            },
            {
              "url": "https://github.com/RensTillmann/super-forms/pull/205"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-07-16T17:31:50.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-09-30T20:15:01.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Super Forms \u003c= 6.3.316 - Authenticated (Subscriber+) Arbitrary File/Directory Deletion via \u0027subdir\u0027 / \u0027path\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-15983",
        "datePublished": "2026-10-01T08:28:41.509Z",
        "dateReserved": "2026-07-16T17:09:44.014Z",
        "dateUpdated": "2026-10-01T08:28:41.509Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-15989 (GCVE-0-2026-15989)

    Vulnerability from cvelistv5 – Published: 2026-10-01 07:40 – Updated: 2026-10-01 13:47
    VLAI
    Title
    Super Forms <= 6.3.316 - Unauthenticated Privilege Escalation via 'role' Parameter
    Summary
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register & Login add-on's before_email_success_msg() function whitelisting the client-submitted 'role' key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action='register').
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-10-01 13:43 UTC
    CWE
    • CWE-269 - Improper Privilege Management
    Impacted products
    Vendor Product Version
    WebRehab Super Forms – Drag & Drop Form Builder Affected: 0 , ≤ 6.3.316 (semver)
    Create a notification for this product.
    Credits
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-15989",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-10-01T13:43:13.238462Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-10-01T13:47:45.799Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Super Forms \u2013 Drag \u0026 Drop Form Builder",
              "vendor": "WebRehab",
              "versions": [
                {
                  "lessThanOrEqual": "6.3.316",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "d.v4n_s3c"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Super Forms \u2013 Drag \u0026 Drop Form Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3.316. This is due to the Register \u0026 Login add-on\u0027s before_email_success_msg() function whitelisting the client-submitted \u0027role\u0027 key and copying it into the user-data array that is passed directly to wp_insert_user(), without validating the submitted role against the administrator-configured register_user_role, without an allow-list, and without any current_user_can() capability check. This makes it possible for unauthenticated attackers to register a new account with the Administrator role by injecting role=administrator into the data submitted to any published Super Forms registration form (register_login_action=\u0027register\u0027)."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-269",
                  "description": "CWE-269 Improper Privilege Management",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-10-01T07:40:23.893Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/7eb62d35-3f0e-4733-8f7f-723d0f25b710?source=cve"
            },
            {
              "url": "https://github.com/RensTillmann/super-forms/pull/205"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-07-16T19:55:18.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-09-30T19:23:33.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Super Forms \u003c= 6.3.316 - Unauthenticated Privilege Escalation via \u0027role\u0027 Parameter"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-15989",
        "datePublished": "2026-10-01T07:40:23.893Z",
        "dateReserved": "2026-07-16T19:39:59.927Z",
        "dateUpdated": "2026-10-01T13:47:45.799Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }

    CVE-2026-14894 (GCVE-0-2026-14894)

    Vulnerability from cvelistv5 – Published: 2026-07-10 02:30 – Updated: 2026-07-10 14:10
    VLAI Previdian
    Title
    Super Forms <= 6.3.313 - Unauthenticated Arbitrary File Upload via 'data' Parameter (datauristring / value)
    Summary
    The Super Forms – Drag & Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce requirement is trivially bypassed because the super_create_nonce nopriv AJAX action allows any unauthenticated visitor to mint a valid sf_nonce and session cookie in a single prior request, reducing exploitation to two unauthenticated HTTP requests.
    SSVC
    Exploitation: none Automatable: yes Technical Impact: total
    CISA Coordinator · CISA-ADP (v2.0.3)
    Decision recorded 2026-07-10 14:07 UTC
    CWE
    • CWE-434 - Unrestricted Upload of File with Dangerous Type
    Impacted products
    Vendor Product Version
    WebRehab Super Forms – Drag & Drop Form Builder Affected: 0 , ≤ 6.3.313 (semver)
    Create a notification for this product.
    Show details on NVD website

    {
      "containers": {
        "adp": [
          {
            "metrics": [
              {
                "other": {
                  "content": {
                    "id": "CVE-2026-14894",
                    "options": [
                      {
                        "Exploitation": "none"
                      },
                      {
                        "Automatable": "yes"
                      },
                      {
                        "Technical Impact": "total"
                      }
                    ],
                    "role": "CISA Coordinator",
                    "timestamp": "2026-07-10T14:07:33.536107Z",
                    "version": "2.0.3"
                  },
                  "type": "ssvc"
                }
              }
            ],
            "providerMetadata": {
              "dateUpdated": "2026-07-10T14:10:37.476Z",
              "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
              "shortName": "CISA-ADP"
            },
            "title": "CISA ADP Vulnrichment"
          }
        ],
        "cna": {
          "affected": [
            {
              "defaultStatus": "unaffected",
              "product": "Super Forms \u2013 Drag \u0026 Drop Form Builder",
              "vendor": "WebRehab",
              "versions": [
                {
                  "lessThanOrEqual": "6.3.313",
                  "status": "affected",
                  "version": "0",
                  "versionType": "semver"
                }
              ]
            }
          ],
          "credits": [
            {
              "lang": "en",
              "type": "finder",
              "value": "andrea bocchetti"
            }
          ],
          "descriptions": [
            {
              "lang": "en",
              "value": "The Super Forms \u2013 Drag \u0026 Drop Form Builder plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 6.3.313 via the submit_form function. This is due to missing file type validation and the absence of any capability check on the submit_form nopriv AJAX handler, whose only barrier is a session nonce freely obtainable by unauthenticated visitors via a separate nopriv endpoint. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible. The nonce requirement is trivially bypassed because the super_create_nonce nopriv AJAX action allows any unauthenticated visitor to mint a valid sf_nonce and session cookie in a single prior request, reducing exploitation to two unauthenticated HTTP requests."
            }
          ],
          "metrics": [
            {
              "cvssV3_1": {
                "baseScore": 9.8,
                "baseSeverity": "CRITICAL",
                "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
                "version": "3.1"
              }
            }
          ],
          "problemTypes": [
            {
              "descriptions": [
                {
                  "cweId": "CWE-434",
                  "description": "CWE-434 Unrestricted Upload of File with Dangerous Type",
                  "lang": "en",
                  "type": "CWE"
                }
              ]
            }
          ],
          "providerMetadata": {
            "dateUpdated": "2026-07-10T02:30:40.490Z",
            "orgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
            "shortName": "Wordfence"
          },
          "references": [
            {
              "url": "https://www.wordfence.com/threat-intel/vulnerabilities/id/e9c7fb16-efbb-41e9-be13-98e96c1e9100?source=cve"
            },
            {
              "url": "https://github.com/RensTillmann/super-forms/commit/c5838f5877c72b738c54ed970935c77ae6830c3a"
            }
          ],
          "timeline": [
            {
              "lang": "en",
              "time": "2026-07-07T15:30:38.000Z",
              "value": "Vendor Notified"
            },
            {
              "lang": "en",
              "time": "2026-07-09T13:41:24.000Z",
              "value": "Disclosed"
            }
          ],
          "title": "Super Forms \u003c= 6.3.313 - Unauthenticated Arbitrary File Upload via \u0027data\u0027 Parameter (datauristring / value)"
        }
      },
      "cveMetadata": {
        "assignerOrgId": "b15e7b5b-3da4-40ae-a43c-f7aa60e62599",
        "assignerShortName": "Wordfence",
        "cveId": "CVE-2026-14894",
        "datePublished": "2026-07-10T02:30:40.490Z",
        "dateReserved": "2026-07-06T18:28:42.679Z",
        "dateUpdated": "2026-07-10T14:10:37.476Z",
        "state": "PUBLISHED"
      },
      "dataType": "CVE_RECORD",
      "dataVersion": "5.2"
    }