SEPTEMBER 8, 2026
Subscribe
Global Press Media · World Report
Technology

Major Vulnerabilities in Elementor Pro and Super Forms Endanger More Than Six Million WordPress Sites

Major Vulnerabilities in Elementor Pro and Super Forms Endanger More Than Six Million WordPress Sites

Wordfence, a security company, cautioned that two critical flaws in the Elementor Pro page‑builder and the Super Forms plugin leave over six million WordPress sites vulnerable to remote code execution attacks.

Both issues rely on the same exploit method: they permit any online user to upload a file to an unprotected site without needing credentials. After the hostile file lands on the server, an attacker can run arbitrary code and possibly seize complete control of the affected site.

Following the public disclosures, Wordfence’s monitoring systems have recorded more than 440,000 attempts to exploit the vulnerabilities. This high volume indicates that malicious actors are actively probing for unpatched installations, using the unauthenticated upload capability to launch automated attacks on a large scale.

The developers of both plugins acted swiftly, releasing patches that block the upload routes and reinforce input validation. Wordfence’s advisory advises site administrators to promptly upgrade to the newest versions and confirm the patches are in place, since earlier releases stay exposed.

WordPress runs about 40% of all publicly accessible websites, and its modular design depends heavily on third‑party plugins. Although this adaptability fuels its popularity, it also expands the attack surface; widely used add‑ons such as Elementor Pro and Super Forms are present on millions of sites, rendering them appealing targets for cyber‑criminals.

Specialists advise administrators to not only install the updates but also inspect server logs for evidence of illicit file uploads, enforce strict file‑type policies, and contemplate extra hardening steps like web‑application firewalls. As the platform evolves, ongoing vigilance and prompt patching stay the best protection against comparable risks.

Source: TechRadar
Editorial Desk — Editorial desk.

Comments (0)

Be the first to comment.

Join the discussion

Protected by reCAPTCHA v3

Related