Critical 9.8
CVE-2026-14894
Mass Exploitation Attempts Against WordPress Super Forms Plugin (CVE-2026-14894)
Vendor / product: Super Forms
Event date: 2026-07-10
Public PoC: Yes
First tracked by RiskWire: 2026-09-04
Sources & citations (2)
- Security Check-in Quick Hits: Mass WordPress Plugin RCE Attacks, Chrome V8 Zero-Day, Thomson Reuters Court Data Breach & SonicWall Edge Zero-Days rodtrent.substack.com · 2026-09-04
- Critical Super Forms WordPress Flaw Actively Exploited to Achieve Remote Code Execution gbhackers.com · 2026-09-04
References
See CVE-2026-14894 in context
RiskWire tracks every exploited CVE this week, cross-referenced against CISA KEV with federal remediation deadlines. Filtered to your vendor stack.
Book a 20-min demo →