VMTech
Discuss a project

WordPress Plugin RCE Flaws Draw More Than 440,000 Exploit Attempts

WordPress Plugin RCE Flaws Draw More Than 440,000 Exploit Attempts

Wordfence blocks mass exploitation attempts

Wordfence has reported more than 440,000 exploit attempts targeting two critical remote-code-execution vulnerabilities in the WordPress plugins Super Forms – Drag & Drop Form Builder and Elementor Pro. The activity targets CVE-2026-14894 in Super Forms and CVE-2026-32475 in Elementor Pro, both of which can allow unauthenticated attackers to upload executable PHP files.

Wordfence said it had blocked more than 250,000 attempts against the Super Forms flaw and more than 190,000 against the Elementor Pro flaw. Super Forms fixed CVE-2026-14894, which has a CVSS score of 9.8, in version 6.3.314. Elementor Pro fixed CVE-2026-32475 in version 4.2.2; the issue is rated 9.0/9.8 in the report.

Arbitrary file-upload flaws can enable an attacker to place a PHP web shell on a vulnerable website and execute arbitrary code. That access may then be used to create administrator accounts, exfiltrate data or take control of a WordPress site.

How the two upload bypasses are being used

For Super Forms, attackers send an HTTP POST request to /wp-admin/admin-ajax.php through the super_submit_form endpoint. The request includes a file field holding a Base64-encoded PHP payload and an attacker-controlled filename. Wordfence observed payloads presented as data:image/gif;base64 content but written as PHP uploader web shells.

The Super Forms activity began on July 14, 2026, and exceeded 40,000 exploit requests at its August 18 peak. The uploaded web shell can act as a conduit for placing further payloads on the compromised site.

Elementor Pro exploitation began on August 19, 2026. In this technique, the attacker submits the Form widget's File Upload field as an array: the first element is empty and the second contains a PHP payload with a .php filename. Wordfence said this structure triggers the validation bypass.

Successful exploitation of the Elementor Pro issue requires a published Elementor page containing a Form widget with a File Upload field. The uploaded file is stored under /wp-content/uploads/elementor/forms/ using a randomly generated filename while retaining the attacker-supplied PHP extension, enabling a direct request to execute commands on the server.

Actions for WordPress site operators

Patchstack disclosed details of CVE-2026-32475 last month, while Wordfence published the two exploitation reports this week. The active volume makes version verification important for organizations that use either affected plugin.

Businesses running Super Forms or Elementor Pro should apply the available fixes immediately, scan sites for indicators of compromise, and audit for unexpected or recently modified .php files. These checks are particularly important where vulnerable versions were exposed while the exploit campaigns were active.

#wordpress#websecurity#vulnerability#rcesecurity
Open analytics
On the site 1 views
min read 3 04.09.2026
Instagram

WordPress Plugin RCE Flaws Draw More Than 440,000 Exploit Attempts

Open the post on Instagram ↗