Critical WordPress Plugin Flaws Put 6 Million Sites at Risk as 440,000 Exploit Attempts Are Blocked
Two critical WordPress plugin flaws put over 6 million sites at risk; 440,000 exploit attempts blocked.
Elementor Pro is a commercial drag-and-drop website builder with more than six million active sites. Wordfence said all versions up to and including 4.2.1 contain an unrestricted file type upload vulnerability tracked as CVE-2026-32475. The flaw has a severity score of 9.8 out of 10 and enables unauthenticated attackers to upload executable files, making remote code execution possible. Exploitation requires the targeted site to have published a page with an Elementor Pro Form widget that includes at least one non-required File Upload field. The issue was patched in mid-August 2026, but Wordfence has already blocked more than 190,000 exploit attempts.
The second bug affects Super Forms, a drag-and-drop form builder with about 13,000 active installations. In versions up to and including 6.3.313, the plugin allowed arbitrary file uploads. Tracked as CVE-2026-14894, the issue also carries a 9.8 severity score and permits unauthenticated attackers to upload potentially executable files, the researchers said. The vendor released a patch several weeks ago. Wordfence observed more than 250,000 exploitation attempts against this vulnerability.
Combined, Wordfence recorded more than 440,000 exploit attempts for the two flaws. Given the widespread use of the plugins and active exploitation, affected site owners are advised to apply the available updates immediately.
Editor's Summary
Wordfence disclosed two critical file-upload vulnerabilities in Elementor Pro and Super Forms, with a combined severity score of 9.8 and more than 440,000 observed exploit attempts. Elementor Pro's issue affects over six million sites; both plugins have received patches, and administrators should update promptly.