Wordfence says threat actors are exploiting critical file upload flaws in the Super Forms and Elementor Pro WordPress plugins, with both issues enabling unauthenticated remote code execution. Site owners are urged to patch immediately, check for compromised PHP files, and review their installs for signs of abuse linked to Mushr00w_upl.php and malicious upload activity. #SuperForms #ElementorPro #CVE-2026-14894 #CVE-2026-32475 #Mushr00w_upl.php
Keypoints
- Wordfence observed active exploitation of Super Forms and Elementor Pro vulnerabilities.
- CVE-2026-14894 allows unauthenticated attackers to upload arbitrary files, including PHP.
- CVE-2026-32475 can be abused to upload PHP files through Elementor Pro forms.
- Wordfence blocked more than 250,000 and 190,000 exploit attempts for the two flaws.
- Administrators should patch, inspect for unexpected .php files, and hunt for indicators of compromise.
Read More: https://thehackernews.com/2026/09/over-440000-exploit-attempts-target.html