< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-09-04T14:18:45+05:30

Over 440,000 Exploit Attempts Target RCE Vulnerabilities in Super Forms and Elementor Pro

Over 440,000 exploit attempts targeting remote code execution (RCE) vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475) have been blocked by Wordfence. These critical flaws (CVSS scores 9.8 and 9.0) allow unauthenticated attackers to upload malicious files, leading to potential site compromise if not patched promptly.

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.

The vulnerabilities in question are -

CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

Read original article

*** END OF TRANSMISSION ***