CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

September 4, 2026

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws Ravie LakshmananSep 04, 2026Vulnerability / Web Security Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are – CVE-2026-14894 (CVSS score: 9.8) – A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including executable PHP files, leading to remote code execution. (Fixed in version 6.3.314) CVE-2026-32475 (CVSS score: 9.0/9.8) – A vulnerability in Elementor Pro that allows unauthenticated attackers to upload files of any type, including executable PHP files, leading to remote code execution. (Fixed in…

CVEs: CVE-2026-14894, CVE-2026-32475