NewsGator+
All NewsTechnologyScienceSportsBusinessLifestyleShowbizWorld
Weekly Brief
NewsGator+
All NewsTechnologyScienceSportsBusinessLifestyleShowbizWorld
Weekly Brief
  1. Home
  2. /
  3. Technology
  4. /
  5. Two major security flaws are affecting more than s...
Technology

Two major security flaws are affecting more than six million WordPress websites

More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild.

3 min read
Two major security flaws are affecting more than six million WordPress websites
Executive DigestOriginal Reporting by TechRadar

This is a curated overview of the story reported by TechRadar. Full text remains copyright of the publisher.

Read Full Story on TechRadar →
  • Wordfence discloses two critical flaws in Elementor Pro and Super Forms
  • Bugs allow unauthenticated arbitrary file uploads, enabling remote code execution; both patched recently
  • Exploitation attempts already exceed 440,000

More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild.

Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms - two popular WordPress plugins.

Elementor Pro is a commercial plugin that allows users to build websites using drag-and-drop elements instead of code. With it, they can add advanced widgets, templates, different forms, popups, and more. It is quite a popular solution with more than six million websites actively using it.

Two bugs, hundreds of thousands of attacks

According to Wordfence, up until recently, it was vulnerable to an “unrestricted file type upload” bug in all versions up to, and including, 4.2.1. “This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained. “This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.”

The bug is tracked as CVE-2026-32475, carries a severity score of 9.8/10 (critical), and was patched in mid-August 2026. So far, Wordfence alone blocked more than 190,000 exploit attempts.

At roughly the same time, the researchers also reported finding a flaw in Super Forms, a form builder plugin that lets users create and manage forms using a drag-and-drop interface. This plugin, with some 13,000 active installations, contained a bug that allowed arbitrary file upload in all versions up to, and including, 6.3.313.

“This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible,” the researchers explained.

This one is tracked as CVE-2026-14894, also carries a severity score of 9.8/10 (critical) and it, too, was patched a few weeks ago. For this flaw, Wordfence observed more than 250,000 exploitation attempts meaning that cumulatively, these two resulted in 440,000 attacks already.

Given the widespread adoption of these plugins, and the fact that the flaws are being actively leveraged, users are advised to apply the fixes without delay.

Via The Hacker News

#Security#Cyber Security#Computing Security#Pro#Computing
0 views0 shares
Sead Fadilpašić
September 7, 2026
5:45 PM
0 comments
Join the discussion
Category
Technology
Original source
Read at source →
0
0

Related Articles

Salesforce has built the TSA a new AI agent to make travelling less awful for everyone
TechRadar·16h ago·Technology

Salesforce has built the TSA a new AI agent to make travelling less awful for everyone

Salesforce has revealed Ace, a new AI agent for the TSAAce should take the pressure of answering basic questions off human agentsAce has already resolved 96% of basic inquiries so farSalesforce has built the Transportation Security Administration (TSA) a new AI agent to try and help streamline trave…

Nvidia RTX 5090 GPU prices skyrocket to $9,000 — as fresh RTX 6000 rumor suggests a 2027 launch that fills me with dread
TechRadar·16h ago·Technology

Nvidia RTX 5090 GPU prices skyrocket to $9,000 — as fresh RTX 6000 rumor suggests a 2027 launch that fills me with dread

Nvidia's RTX 5090 is now over $9,000 in the USA new rumor suggests that RTX 6000 gaming GPUs are coming in 2027, maybe in the first half of the yearIf true, the price tag that's attached to the RTX 6090 will likely be colossal, and lower-tier GPUs could be pricey tooNvidia's RTX 5090 flagship has hi…

Considering a Level 2 EV charger? How to know if you need one
Engadget·16h ago·Technology

Considering a Level 2 EV charger? How to know if you need one

Charging your EV from home is cheap and convenient, but knowing which type of charger will get the most out of your electric car can often be confusing.

India escalates Apple probe over alleged iOS 18 issues that incurred repair costs
9to5Mac·16h ago·Technology

India escalates Apple probe over alleged iOS 18 issues that incurred repair costs

India’s Central Consumer Protection Authority (CCPA) has reportedly escalated its probe into whether Apple should be held responsible for an iOS 18 update that allegedly caused display and microphone issues on some iPhones. Here are the details. more…

Stay Informed.

The day's biggest stories, curated and trusted.

Browse CategoriesSearch Articles
NewsGator .
Privacy PolicyTerms of ServiceContactAbout Us
© 2026 NewsGator. Aggregating news from trusted sources.