ZeroHour
Wordfencepublished ()ingested István Márton

Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin

highExploit / PoC exploited in the wildimportance 58
AI summary · glm-5.3-flash

Attackers are actively exploiting a critical unauthenticated file upload flaw in the Super Forms WordPress plugin to deploy PHP backdoors for RCE.

Wordfence disclosed on July 9, 2026 a critical unauthenticated arbitrary file upload vulnerability in the Super Forms WordPress plugin, which has roughly 13,000 active installations. Unauthenticated attackers can upload arbitrary files, including PHP backdoors, to achieve remote code execution. The vendor now reports that attackers are actively exploiting the flaw in the wild.

  • Unauthenticated arbitrary file upload enables PHP backdoor deployment and remote code execution.
  • Plugin has an estimated 13,000 active installations, limiting but not eliminating exposure.
  • Flaw was publicly disclosed on July 9, 2026 and exploitation is now observed.
VendorsWordfence
ProductsSuper Forms
Full article

On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The post Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin appeared first on Wordfence.

The full text could not be extracted from this site (paywall, bot protection or heavy scripting). Read it at wordfence.com.