Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
AI-summarised brief · reviewed before publication
Wordfence reported that actors have launched over 440,000 exploit attempts against two WordPress plugin flaws – CVE‑2026‑14894 in Super Forms and CVE‑2026‑32475 in Elementor Pro. Both vulnerabilities allow file upload, enabling attackers to place a PHP web shell in the site’s uploads directory and execute code, create admin accounts, or exfiltrate data. Exploits of CVE‑2026‑14894 involve POST requests to /wp‑admin/admin‑ajax.php with a Base64‑encoded PHP payload disguised as an image, while CVE‑2026‑32475 attacks require a published Elementor page containing a Form widget with a File Upload field. Wordfence blocked roughly 250,000 attempts on Super Forms flaw and 190,000 on Elementor flaw. Campaigns began in July and peaked in August 2026. Site owners are urged to apply patches