AI Weekly Malaysia

Back to items Summaries

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

ID
21412
Status
summarized
Published
04 Sep 2026, 4:48 PM
Fetched
04 Sep 2026, 6:37 PM
Provider
The Hacker News
Category
security
Original URL
https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html
Source URL
https://feeds.feedburner.com/TheHackersNews

Summary

Score
6.5
Created
04 Sep 2026, 6:38 PM
Tags
Audience
developerssaas_founders

What happened

Wordfence reports over 440,000 exploit attempts against two critical WordPress plugin RCE flaws: CVE-2026-14894 (Super Forms, CVSS 9.8, fixed in v6.3.314) and CVE-2026-32475 (Elementor Pro, CVSS 9.0/9.8, fixed in v4.2.2). Both allow unauthenticated attackers to upload arbitrary PHP files via form file-upload fields, enabling web shells, admin account creation, and full site takeover.

Why it matters

If you run WordPress with Super Forms below 6.3.314 or Elementor Pro below 4.2.2—and especially if any published page uses an Elementor Form widget with a File Upload field—patch now or disable the file upload field immediately. The attack is trivially scriptable via a single POST to /wp-admin/admin-ajax.php with a Base64-encoded PHP payload.

Discussion angle

Many Malaysian SMB and agency sites run Elementor Pro; this is a good moment to discuss whether file-upload form widgets should be exposed to unauthenticated users at all, and how to audit client sites for this specific configuration.

Top