Back to advisories

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are actively exploiting two critical RCE vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475), with over 440,000 exploit attempts already blocked. Unauthenticated attackers can upload arbitrary files including PHP web shells to gain full site compromise. Any organization running these plugins on unpatched WordPress installations is at immediate risk of takeover.

CRITICALAdvisorySep 05, 2026
Action required
Immediately scan all WordPress instances for Super Forms and Elementor Pro installations. Patch both plugins to latest versions or disable them if not critical. Threat hunt for web shells in wp-content and wp-uploads directories on affected systems. Block exploitation patterns at WAF/IPS level.
Affected products
Super FormsElementor ProWordPressWordfencePatchstack