← Back to blog

WordPress Plugin Flaws Targeted in 440K+ Exploit Attempts

Critical vulnerabilities in Super Forms and Elementor Pro are under active exploitation. Unauthenticated attackers can achieve remote code execution through file upload flaws.

TL;DR

  • Over 440,000 exploit attempts hit WordPress plugins Super Forms and Elementor Pro
  • CVE-2026-14894 in Super Forms lacks file validation, allowing arbitrary uploads
  • Elementor Pro also suffers from a critical RCE flaw being exploited
  • Attacks are unauthenticated, making them accessible to any remote attacker
  • Immediate updates are recommended for site administrators

Security researchers at Wordfence have identified a surge in exploit attempts targeting two widely used WordPress plugins. The affected plugins, Super Forms and Elementor Pro, contain critical vulnerabilities that allow unauthenticated attackers to execute arbitrary code on vulnerable sites.

These exploits have been observed over 440,000 times in the wild, highlighting the urgency for website administrators to patch their systems immediately. Both vulnerabilities enable attackers to bypass security controls and gain full control of affected websites without requiring authentication.

Vulnerability Details

  • CVE-2026-14894 affects Super Forms with a CVSS score of 9.8
  • Missing file type validation allows upload of malicious files
  • Elementor Pro contains separate RCE vulnerability also being exploited
  • Both flaws can be exploited without authentication
  • Successful exploitation grants attackers full control of affected websites

Security Recommendations

  • Update Super Forms and Elementor Pro to latest patched versions immediately
  • Monitor server logs for suspicious file uploads or unusual activity
  • Implement web application firewalls to filter malicious requests
  • Consider temporarily disabling affected plugins if updates aren't possible
  • Audit existing installations for signs of compromise or backdoor files

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

WordPress Plugin Flaws Targeted in 440K+ Exploit Attempts — Agent Breach Blog | Agent Breach