← Back to feed
vendor Wordfence Blog

Attackers Actively Exploiting Critical Vulnerability in Super Forms Plugin

Wordfence Blog WordPress

On July 9th, 2026, we publicly disclosed a critical Unauthenticated Arbitrary File Upload vulnerability in Super Forms, a WordPress plugin with an estimated ...

T1190
Read the full story Wordfence Blog →

Related Coverage

vendor PSA: Critical Unauthenticated Path Traversal Vulnerability Patched in WordPress Core Wordfence Blog · Sep 22 vendor Unmasking EvilTokens: Getting to the root of device code phishing Microsoft Security Blog · Sep 22 vendor Inside a Malicious, Stealthy WordPress Must Use Plugin Wordfence Blog · Sep 22