Super Forms upload bug draws 250,000 blocked exploit tries

Wordfence counts 440,000 exploit attempts against Super Forms and Elementor Pro file-upload flaws.

CSBadmin
1 Min Read

Wordfence says it has blocked more than 440,000 exploit attempts against two WordPress plugins, Super Forms and Elementor Pro, as attackers race to weaponize file-upload flaws that end in remote code execution.

The larger share, over 250,000 blocked attempts, targets CVE-2026-14894, a missing file-type validation bug in the Super Forms drag-and-drop builder that lets unauthenticated attackers upload files of any type, including executable PHP. The fix shipped in version 6.3.314. Observed attacks POST to the super_submit_form action under wp-admin/admin-ajax.php with a Base64-encoded PHP payload and an attacker-controlled filename in the file field.

The remaining roughly 190,000 attempts hit CVE-2026-32475 in Elementor Pro, a similar arbitrary file upload flaw fixed in version 4.2.2 and disclosed by Patchstack last month. Exploitation requires the target site to run at least one published Elementor page with a Form widget that includes a File Upload field.

Both bugs let an attacker write a PHP web shell to the server, then create administrator accounts, exfiltrate data, or seize the site outright.

Site owners running either plugin should update immediately. Administrators should also review admin-ajax traffic for super_submit_form requests, scan upload directories for unexpected PHP files, and audit recently created admin accounts.

CSBadmin

The latest in cybersecurity news and updates.

Share This Article
Follow:
The latest in cybersecurity news and updates.