LIVE · cybersecurity feed
Live wire
CVE-2026-14894 · Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsCisco searched for IOS XR bugs and found so many it rolled them into an update releaseAttackers exploit zero-days in consistently besieged SonicWall productIntroducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak modelsHPE patches critical ArubaOS-CX remote code execution flawCVE-2026-82329 · Attackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-0768 · Critical Langflow flaw exploited to steal OpenAI and AWS keysCVE-2026-82329 · Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureCVE-2026-82329 · Critical JFrog Artifactory Vulnerability Reportedly Exploited in the WildHackers Are Probing PaperCut Servers, and 47% Still Have No Patch
CVE-2026-14894critical

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

zeroday.news ·

Wordfence has reported a significant volume of exploit attempts targeting two distinct critical remote code execution (RCE) vulnerabilities in popular WordPress plugins: Super Forms and Elementor Pro. Over 440,000 exploit attempts have been observed, indicating widespread malicious activity aimed at leveraging these flaws.

One of the vulnerabilities, identified as CVE-2026-14894 with a CVSS score of 9.8, affects the Super Forms – Drag & Drop Form Builder plugin. This flaw is described as a missing file type validation vulnerability. It allows unauthenticated attackers to upload arbitrary file types to affected WordPress installations.

The technical mechanism behind CVE-2026-14894 typically involves a web application failing to properly sanitize or validate user-supplied input, specifically regarding file uploads. In this case, the absence of file type validation means an attacker can bypass restrictions designed to only permit safe file types (like images or documents) and instead upload malicious scripts, such as PHP files. Once uploaded, if the web server is configured to execute these files, the attacker can achieve remote code execution, gaining control over the compromised server.

Products in the category of WordPress form builders and page builders are frequently targeted due to their widespread use and their common inclusion of file upload functionalities. The potential scope of impact for such vulnerabilities is broad, encompassing any website running the vulnerable versions of Super Forms. Attackers often scan for specific plugin fingerprints to identify vulnerable targets at scale.

Mitigation for this class of issue typically involves several steps. Website administrators should immediately update the Super Forms plugin to the latest patched version. If an update is not yet available, disabling the plugin or implementing web application firewall (WAF) rules to block suspicious upload requests can provide temporary protection. Regular security audits and ensuring all WordPress core, themes, and plugins are kept up-to-date are fundamental best practices.

The second vulnerability, affecting Elementor Pro, is also described as an RCE flaw, though specific details beyond its existence were not provided in the summary. Elementor Pro is another widely used WordPress plugin, and an RCE vulnerability in such a popular tool presents a similar high risk.

The high volume of exploit attempts underscores the persistent threat posed by vulnerabilities in widely used content management system plugins. Attackers consistently target popular platforms like WordPress, knowing that a single vulnerability can open doors to hundreds of thousands of potential victims. This incident highlights the critical importance of timely patching and robust security practices for all website administrators.

vulnerabilitycloud
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Most of the bugs Claude Mythos found have never been checked by a human

Anthropic pointed Claude Mythos Preview at 281 open-source projects and collected 23,019 candidate vulnerabilities. External security firms reviewed 1,900 of them. Maintainers received 1,596 reports and acknowledged 1,451; 97 fixes landed upstream, and 88 findings became published security advisories, with counts current as of May 22, 2026. The other 21,119 candidates have not been reviewed by any

vulnerability

New infosec products of the week: September 4, 2026

Here’s a look at the most interesting products from the past week, featuring releases from BugBase, F5 Networks, Ping Identity, and Superna. F5 speeds up virtual patching to counter AI-driven threats With new features such as anomaly detection and agentic threat intelligence, F5’s AI-powered web application firewall (WAF) is capable in delivering real-time protections because of its strategic posi

vulnerabilitycritical

Cisco searched for IOS XR bugs and found so many it rolled them into an update release

Three critical vulns demand your attention, one a make-me-root mess in Nexus 9000 Series Switches that you can mitigate, not fix

ai

[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

ai

[Virtual Event] Building a Secure AI Strategy for the Enterprise

nation-state

G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules

The G7 has published a call to action, urging governments to launch national strategies dedicated to the post-quantum encryption transition