THREATOPS
THREAT OPSThreat News › Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

medthehackernewsPublished 2026-09-04

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.

The vulnerabilities in question are -

CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html