THREATOPS
THREAT OPSThreat News › Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin

Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin

medwordfencePublished 2026-09-03

<p>On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in <a href="https://super-forms.com" rel="noopener" target="_blank">Super Forms</a>, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code e

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://www.wordfence.com/blog/2026/09/attackers-actively-exploiting-critical-vulnerability-in-super-forms-plugin/