← WordPress Vulnerabilities
WordPress security by component

Super Forms – Drag & Drop Form Builder

Super Forms – Drag & Drop Form Builder is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 10, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: super-forms-drag-drop-form-builder

CVE-2026-14894: Super Forms – Drag & Drop Form Builder: Dangerous file upload

Super Forms – Drag & Drop Form Builder is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 6.3.313.

PublishedJul 10, 2026
Known safe version> 6.3.313
Safe version
Jul 10, 2026 CVE-2026-14894
Super Forms – Drag & Drop Form Builder: Dangerous file upload
Super Forms – Drag & Drop Form Builder is affected by dangerous file upload. The vulnerable path is reachable without authentication. Successful exploitation can place attacker-controlled executable content on the server and may lead to full site compromise. The published affected range is <= 6.3.313.
> 6.3.313
CVE9.8
NVDPending