CVE Tools
Back to feed
Exploited in the wild Super Forms rce Elementor Pro WordPress web-app

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

The Hacker News·By The Hacker News··3 min read
CVE Tools coverage

Wordfence has reported active exploitation of two critical remote code execution vulnerabilities affecting the WordPress plugins Super Forms and Elementor Pro, with over 440,000 attempted attacks recorded so far.

CVE-2026-14894 (CVSS 9.8) in Super Forms – Drag & Drop Form Builder enables unauthenticated users to upload arbitrary PHP files due to missing file type validation, a flaw fixed in version 6.3.314. Similarly, CVE-2026-32475 (CVSS 9.0/9.8) in Elementor Pro allows unrestricted file uploads through form widgets, leading to code execution on systems patched in version 4.2.2.

Attackers are using these flaws to deploy web shells, such as "Mushr00w_upl.php," to gain full control of compromised sites. Site administrators should update both plugins immediately and scan for unauthorized modifications to mitigate this ongoing threat.