On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated 13,000 active installations. This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution. The vendor released the fully patched version on July 8th, 2026, and we disclosed this vulnerability in the Wordfence Intelligence vulnerability database on July 9th, 2026. Our records indicate that attackers started exploiting the issue on July 14th, 2026, the same day we released the firewall rule. The Wordfence Firewall has already blocked over

Click here to continue reading this article.