As cited
Copy frozen at (site build).
vulnerabilities
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are actively exploiting CVE-2026-14894, a critical remote code execution flaw in the Super Forms WordPress plugin, with over 440,000 exploit attempts recorded. The vulnerability, scored 9.8 on CVSS version 3.1, stems from missing file type validation that permits unauthenticated file uploads.
Why it matters: WordPress site administrators running Super Forms or Elementor Pro must patch immediately, as this high-severity remote code execution vulnerability is under active exploitation with hundreds of thousands of attack attempts.
- Source published
- First seen by Cybersecurity Tracker
Source attribution
Correction
Correction recorded as of .
vulnerabilities
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Threat actors are actively exploiting CVE-2026-14894, a critical remote code execution flaw in the Super Forms WordPress plugin, with over 440,000 exploit attempts recorded. The vulnerability, scored 9.8 on CVSS version 3.1, stems from missing file type validation that permits unauthenticated file uploads.
Why it matters: WordPress site administrators running Super Forms or Elementor Pro must patch immediately, as this high-severity remote code execution vulnerability is under active exploitation with hundreds of thousands of attack attempts.
- Source published
- First seen by Cybersecurity Tracker