Security researchers have identified and patched two critical vulnerabilities in two widely used WordPress plugins: Elementor Pro and Super Forms. These flaws allow attackers to upload arbitrary files without authentication, potentially leading to remote code execution, which could enable full control of affected websites. Both issues have been addressed with recent updates.
More than six million WordPress users are at risk, as these vulnerabilities have been actively exploited in the wild. The findings were made by Wordfence, a well-known security firm, which uncovered the flaws in Elementor Pro and Super Forms—two plugins with significant user bases. Elementor Pro, in particular, is a commercial plugin that allows users to create websites using a drag-and-drop interface, and it's used by over six million websites globally.
The vulnerability in Elementor Pro was present in all versions up to and including 4.2.1. It allowed attackers to upload executable files if a page on the site contained an Elementor Pro Form widget with a non-required File Upload field. This flaw, identified as CVE-2026-32475, has a severity score of 9.8 out of 10 (critical) and was fixed in mid-August 2026. Wordfence reported blocking over 190,000 attempts to exploit this vulnerability.
Similarly, Super Forms—a plugin used by about 13,000 websites—had a flaw in versions up to 6.3.313 that allowed unauthenticated users to upload executable files. This vulnerability, tracked as CVE-2026-14894, also has a critical severity score of 9.8 and was patched recently. Wordfence observed over 250,000 attempts to exploit this issue. Together, the two vulnerabilities have been the target of over 440,000 exploitation attempts.
Given the widespread use of these plugins and the active exploitation of the flaws, users are strongly advised to update their installations immediately. Failing to apply the patches could leave websites vulnerable to takeover by malicious actors.
Critical WordPress Plugin Vulnerabilities Exploited in Mass Attacks
AI-rewritten from original reportingHow it works
wordpresssecurityvulnerabilityelementor-prosuper-formsrce



