Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
- ID
- 21412
- Status
- summarized
- Published
- 04 Sep 2026, 4:48 PM
- Fetched
- 04 Sep 2026, 6:37 PM
- Provider
- The Hacker News
- Category
- security
- Original URL
- https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html
- Source URL
- https://feeds.feedburner.com/TheHackersNews
Summary
- Score
- 6.5
- Created
- 04 Sep 2026, 6:38 PM
- Tags
- Audience
- developerssaas_founders
What happened
Wordfence reports over 440,000 exploit attempts against two critical WordPress plugin RCE flaws: CVE-2026-14894 (Super Forms, CVSS 9.8, fixed in v6.3.314) and CVE-2026-32475 (Elementor Pro, CVSS 9.0/9.8, fixed in v4.2.2). Both allow unauthenticated attackers to upload arbitrary PHP files via form file-upload fields, enabling web shells, admin account creation, and full site takeover.
Why it matters
If you run WordPress with Super Forms below 6.3.314 or Elementor Pro below 4.2.2—and especially if any published page uses an Elementor Form widget with a File Upload field—patch now or disable the file upload field immediately. The attack is trivially scriptable via a single POST to /wp-admin/admin-ajax.php with a Base64-encoded PHP payload.
Discussion angle
Many Malaysian SMB and agency sites run Elementor Pro; this is a good moment to discuss whether file-upload form widgets should be exposed to unauthenticated users at all, and how to audit client sites for this specific configuration.