Critical Vulnerabilities Discovered in Elementor Pro and Super Forms
- Wordfence reveals significant security flaws in two widely used WordPress plugins.
- Exploitable bugs permit unauthorized file uploads, potentially leading to remote code execution; patches have been implemented recently.
- Attempts to exploit these vulnerabilities have surpassed 440,000.
Researchers have uncovered alarming vulnerabilities that endanger the websites of more than six million WordPress users, suggesting an imminent risk of malicious takeovers.
The investigation, carried out by security experts at Wordfence, identified two separate bugs—one within Elementor Pro and another in Super Forms, both of which are among the most favored WordPress plugins.
Elementor Pro stands as a commercial plugin that empowers users to construct websites utilizing a drag-and-drop interface, eliminating the need for coding.
It boasts over six million active installations, enabling users to incorporate advanced widgets, templates, various forms, and popups.
Two Critical Bugs, Over 440,000 Exploits
Wordfence has reported that Elementor Pro was previously susceptible to an “unrestricted file type upload” flaw affecting all versions up to and including 4.2.1.
This vulnerability allows unauthenticated attackers to upload potentially executable files, paving the way for remote code execution.
Notably, this exploit can occur if the targeted site has published a page featuring an Elementor Pro Form widget with at least one optional File Upload field.
This particular vulnerability is designated as CVE-2026-32475, possessing a severity rating of 9.8 out of 10, classified as critical.
A patch was introduced in mid-August 2026, following the blocking of over 190,000 exploitation attempts by Wordfence.
Concurrently, researchers disclosed a similar vulnerability in Super Forms, a plugin that permits users to effortlessly create and manage forms through a drag-and-drop interface.
This plugin, which has approximately 13,000 active installations, was vulnerable to arbitrary file uploads across all versions up to and including 6.3.313.
According to Wordfence, this flaw, tracked as CVE-2026-14894, also garners a severity score of 9.8 out of 10 and was similarly patched recently.

It has already seen over 250,000 attempts at exploitation, leading to a cumulative total of more than 440,000 attacks associated with both vulnerabilities.
Given the extensive usage of these plugins and the active exploitation of these vulnerabilities, users are strongly urged to implement the necessary security updates promptly.
Source link: Techradar.com.



