Two major security flaws are affecting more than six million WordPress websites

Security researchers at Wordfence have disclosed two critical vulnerabilities affecting popular WordPress plugins, Elementor Pro and Super Forms. Both flaws, identified as CVE-2026-32475 and CVE-2026-14894, carry a severity score of 9.8/10 and allow unauthenticated attackers to perform arbitrary file uploads, potentially leading to remote code execution. Elementor Pro, which powers over six million websites, and the Super Forms plugin have both been patched in recent updates. However, the situation remains urgent as researchers have already observed over 440,000 exploitation attempts in the wild. The vulnerabilities stem from unrestricted file type uploads, enabling malicious actors to compromise websites. Given the widespread use of these plugins, security experts strongly advise all administrators to verify their plugin versions and apply the latest security patches immediately to prevent potential website takeovers and further malicious activity.
This is a summary. Read the full article at the original source:
TechRadarRelated stories
Security researchers and tech reviewers from Gamers Nexus and Level1Techs have raised concerns regarding the privacy practices of LG televisions. Inve…
Microsoft has released its largest-ever patch bundle, addressing at least 974 security vulnerabilities across its Windows operating systems and softwa…
Microsoft's latest Patch Tuesday update has reached a staggering new record, addressing 974 Common Vulnerabilities and Exposures (CVEs). This massive…



