CRITICALAdvisorySep 05, 2026
Action required
Immediately scan all WordPress instances for Super Forms and Elementor Pro installations. Patch both plugins to latest versions or disable them if not critical. Threat hunt for web shells in wp-content and wp-uploads directories on affected systems. Block exploitation patterns at WAF/IPS level.
Affected products
Super FormsElementor ProWordPressWordfencePatchstack
CVE IDs