CVE Tools

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

The Hacker NewsBy The Hacker News

Reported exploitedSuper FormsElementor Pro

Our summary

Wordfence has reported active exploitation of two critical remote code execution vulnerabilities affecting the WordPress plugins Super Forms and Elementor Pro, with over 440,000 attempted attacks recorded so far.

CVE-2026-14894 (CVSS 9.8) in Super Forms – Drag & Drop Form Builder enables unauthenticated users to upload arbitrary PHP files due to missing file type validation, a flaw fixed in version 6.3.314. Similarly, CVE-2026-32475 (CVSS 9.0/9.8) in Elementor Pro allows unrestricted file uploads through form widgets, leading to code execution on systems patched in version 4.2.2.

Attackers are using these flaws to deploy web shells, such as "Mushr00w_upl.php," to gain full control of compromised sites. Site administrators should update both plugins immediately and scan for unauthorized modifications to mitigate this ongoing threat.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store