🔴 Critical: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
-
Threat actors are actively exploiting two critical remote code execution flaws in popular WordPress plugins, Super Forms – Drag & Drop Form Builder and Elementor Pro, according to research from Wordfence. The campaign has generated over 440,000 exploit attempts, indicating a wide-scale, automated effort to compromise vulnerable sites.
The first vulnerability, CVE-2026-14894 (CVSS score: 9.8), is a missing file type validation issue in Super Forms. This flaw allows unauthenticated attackers to upload files of any type, including PHP webshells, which can be leveraged to achieve full remote code execution on the underlying server.
- The second flaw, related to Elementor Pro, is also actively targeted in these attacks, though specific technical details were not disclosed in the report.
- The high CVSS score and lack of authentication requirement for the Super Forms flaw make it particularly dangerous for unpatched installations.
- Site administrators are urged to immediately update both plugins to their latest patched versions to mitigate the risk of compromise.
Indicators of compromise may include unexpected file uploads in wp-content/uploads directories, particularly
.phpfiles, and suspicious admin user creation events. Monitor access logs for abnormal POST requests to form handlers as a precautionary measure.Source: The Hacker News
Are any of your managed WordPress sites running these plugins, and have you seen any malicious file upload activity in your logs yet?
Hello! It looks like you're interested in this conversation, but you don't have an account yet.
Getting fed up of having to scroll through the same posts each visit? When you register for an account, you'll always come back to exactly where you were before, and choose to be notified of new replies (either via email, or push notification). You'll also be able to save bookmarks and upvote posts to show your appreciation to other community members.
With your input, this post could be even better 💗
Register Login