Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Source: The Hacker News
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.
The vulnerabilities in question are -
CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Dr