Over 440,000 exploit attempts target Super Forms and Elementor Pro flaws
Oleh Zai · Let's Make It Easy
Dipublikasikan 2026-09-04
The practical risk is not the headline number alone: an upload path that accepts executable PHP can become a route to remote code execution.
The practical risk is not the headline number alone: an upload path that accepts executable PHP can become a route to remote code execution.
Apa yang dilaporkan
The Hacker News reports more than 440,000 blocked exploit attempts against two WordPress plugin flaws, based on Wordfence data.
NVD describes CVE-2026-14894 as unauthenticated arbitrary file upload in Super Forms versions through 6.3.313, with CVSS 3.1 score 9.8 from Wordfence.
Detail penting
The fixes cited by The Hacker News are Super Forms 6.3.314 and Elementor Pro 4.2.2.
Catatan dan batas
The NVD record for CVE-2026-32475 was still loading during browser retrieval, so the detailed second-CVE description here follows the readable primary report. Do not infer that every WordPress site is affected.