THREAT OPS › Threat News › Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin
Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin
<p>On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in <a href="https://super-forms.com" rel="noopener" target="_blank">Super Forms</a>, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code e
MITRE ATT&CK techniques
Indicators of compromise
- 8dae08eb7d527264fd4e9c97ea820971md5
- CVE-2026-14894cve
- CVE-2026-48907cve
- https://super-forms.comurl
- https://www.cve.org/CVERecord?id=CVE-2026-14894url
- https://www.cve.org/CVERecord?id=CVE-2026-48907url
- 103.168.146.131ipv4
- 103.168.147.235ipv4
- 103.154.152.178ipv4
- 103.170.97.7ipv4
- 182.10.130.51ipv4
- 189.4.122.140ipv4
- 129.227.46.143ipv4
- 64.176.209.104ipv4
- 103.164.182.122ipv4
- 37.9.33.62ipv4
- www.gravatar.comdomain