<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[🔴 Critical: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws]]></title><description><![CDATA[<p dir="auto">Threat actors are actively exploiting two critical remote code execution flaws in popular WordPress plugins, <strong>Super Forms – Drag &amp; Drop Form Builder</strong> and <strong>Elementor Pro</strong>, according to research from <strong>Wordfence</strong>. The campaign has generated over <strong>440,000 exploit attempts</strong>, indicating a wide-scale, automated effort to compromise vulnerable sites.</p>
<p dir="auto">The first vulnerability, <strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-14894" target="_blank" rel="noopener noreferrer nofollow ugc">CVE-2026-14894</a></strong> (CVSS score: <strong>9.8</strong>), is a missing file type validation issue in Super Forms. This flaw allows unauthenticated attackers to upload files of any type, including PHP webshells, which can be leveraged to achieve full remote code execution on the underlying server.</p>
<ul>
<li>The second flaw, related to Elementor Pro, is also actively targeted in these attacks, though specific technical details were not disclosed in the report.</li>
<li>The high CVSS score and lack of authentication requirement for the Super Forms flaw make it particularly dangerous for unpatched installations.</li>
<li>Site administrators are urged to immediately update both plugins to their latest patched versions to mitigate the risk of compromise.</li>
</ul>
<p dir="auto">Indicators of compromise may include unexpected file uploads in wp-content/uploads directories, particularly <code>.php</code> files, and suspicious admin user creation events. Monitor access logs for abnormal POST requests to form handlers as a precautionary measure.</p>
<p dir="auto">Source: <a href="https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html" target="_blank" rel="noopener noreferrer nofollow ugc">The Hacker News</a></p>
<p dir="auto">Are any of your managed WordPress sites running these plugins, and have you seen any malicious file upload activity in your logs yet?</p>
]]></description><link>https://xploitlk.com/topic/212/critical-over-440-000-exploit-attempts-target-super-forms-and-elementor-pro-rce-flaws</link><generator>RSS for Node</generator><lastBuildDate>Sat, 05 Sep 2026 12:37:43 GMT</lastBuildDate><atom:link href="https://xploitlk.com/topic/212.rss" rel="self" type="application/rss+xml"/><pubDate>Fri, 04 Sep 2026 10:30:23 GMT</pubDate><ttl>60</ttl></channel></rss>