Wordfence reports two critical WordPress plugin flaws exploited in 440,000 attacks

This digest was compiled by AI from multiple sources — links to the originals are below.
Wordfence disclosed two critical vulnerabilities in Elementor Pro and Super Forms, WordPress plugins used by over six million websites. The flaws allow unauthenticated attackers to upload executable files and achieve remote code execution. More than 440,000 exploitation attempts have been blocked since the flaws were patched in August 2026.
Key Facts
- Elementor Pro vulnerability CVE-2026-32475 has a severity score of 9.8/10 and was patched in mid-August 2026.
- Super Forms vulnerability CVE-2026-14894 also has a severity score of 9.8/10 and was patched a few weeks ago.
- Wordfence blocked more than 190,000 exploit attempts targeting Elementor Pro and over 250,000 targeting Super Forms.
- Elementor Pro is used by more than six million websites, while Super Forms has about 13,000 active installations.
Vulnerability Details
Elementor Pro versions up to and including 4.2.1 contained an unrestricted file type upload bug. The flaw allowed unauthenticated attackers to upload executable files, enabling remote code execution. Exploitation required the targeted site to have a published page with an Elementor Pro Form widget containing at least one non-required File Upload field. Super Forms versions up to and including 6.3.313 had a similar arbitrary file upload vulnerability.
Exploitation and Response
Wordfence observed more than 190,000 exploit attempts against Elementor Pro and over 250,000 against Super Forms. Both vulnerabilities were patched in August 2026, with Elementor Pro fixed in mid-August and Super Forms a few weeks ago. Wordfence advises users to apply the fixes without delay due to active exploitation.