Zero Day Room
Live
Vulnerabilities

WordPress Plugins Super Forms and Elementor Pro Hit

Threat actors have launched numerous exploit attempts against critical remote code execution flaws in the WordPress plugins Super Forms and Elementor

Threat actors have launched numerous exploit attempts against critical remote code execution flaws in the WordPress...

Attackers have launched numerous exploit attempts against two critical vulnerabilities in popular WordPress plugins. The security firm Wordfence reported blocking many attempts targeting a flaw in Super Forms and others against a flaw in Elementor Pro. Both vulnerabilities allow unauthenticated attackers to upload executable PHP files, leading to full site compromise.

Wordfence published its findings this week. The flaws are classified as arbitrary file upload vulnerabilities. Successful exploitation lets an attacker write a PHP web shell to a site. This shell can then be used to create administrator accounts, steal data, or take complete control of the WordPress installation. Site owners are urged to apply vendor-issued patches immediately.

Critical Vulnerabilities and Patches

The two vulnerabilities under attack are severe remote code execution flaws. They share a common mechanism but affect different plugins.

CVE IdentifierPluginCVSS ScoreVulnerability DescriptionPatched Version
CVE-2026-14894Super Forms, Drag & Drop Form Builder9.8Missing file type validation allows unauthenticated upload of any file type, including PHP.6.3.314
CVE-2026-32475Elementor Pro9.0/9.8Allows unauthenticated attackers to upload files of any type, leading to remote code execution.4.2.2

Details about the Elementor Pro flaw were first disclosed by Patchstack last month. Wordfence notes that exploiting CVE-2026-32475 requires the targeted site to have at least one published Elementor page containing a Form widget with a File Upload field.

Exploitation of the Super Forms Flaw

Attackers began targeting CVE-2026-14894 on July 14, 2026. Activity peaked on August 18 with many exploit requests in a single day. The attacks involve sending a crafted HTTP POST request to a specific WordPress endpoint.

The request uses the super_submit_form action and includes a Base64-encoded PHP payload disguised as an image file. The uploaded file, named "Mushr00w_upl.php," is a web shell that acts as a conduit for further malicious uploads. Wordfence provided a list of IP addresses linked to this campaign, including 103.168.147.235, 103.168.146.131, and 103.154.152.178.

Exploitation of the Elementor Pro Flaw

Exploitation of CVE-2026-32475 started a day later, on August 19, 2026. Wordfence explained the attack technique. "The attacker submits the form's File Upload field as an array, where the first element is empty and the second element carries a PHP payload with a .php file name, which is the structure that triggers the validation bypass," the company said.

The uploaded PHP file is placed in a specific directory with a random filename but retains the attacker-supplied .php extension. The attacker can then directly request this file to execute commands on the server. Attack IPs for this campaign include 2602:fa59:10:7a1::1, 185.196.220.85, and 103.84.230.85.

Recommendations for Site Owners

WordPress administrators using these plugins must take action. The primary step is to update Super Forms to version 6.3.314 or later and Elementor Pro to version 4.2.2 or later. Site owners should also scan their installations for indicators of compromise. Wordfence recommends auditing web directories for unexpected or recently modified .php files, particularly in upload folders. The attacks demonstrate that unpatched, popular plugins are high-value targets for automated exploitation campaigns seeking server control.

Related coverage

More from Vulnerabilities