WORDPRESS · SEPTEMBER 2026 · EARLY WARNING

Critical Flaws in Super Forms and Elementor Pro Under Active Attack

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
Severity
CRITICAL
CVSS
9.8
Affected component
super-forms (wordpress)
Affected versions
>= v6.3.313, <= v6.3.313
Patched version
Not yet available
CVE-2026-14894

Threat actors are reportedly exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, allowing unauthenticated file uploads and potential remote code execution.

What happened

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro. CVE-2026-14894 in Super Forms allows unauthenticated attackers to upload files of any type, including executable PHP files, leading to remote code execution. Similarly, CVE-2026-32475 in Elementor Pro enables unauthenticated file uploads, which can result in remote code execution. These vulnerabilities can be leveraged to write a PHP web shell to the site and execute arbitrary code, potentially leading to the creation of administrator accounts, data exfiltration, or complete site takeover.

Super Forms versions affected range from 6.3.313 to 6.3.313, while Elementor Pro versions affected range from 6.3.313 to 6.3.313. It is crucial for users of these plugins to upgrade to the latest versions to mitigate the risk of exploitation.

What to do about it

How 0Day would have caught this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If super-forms is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Frequently asked questions

Am I affected?

If you are using Super Forms version 6.3.313 or Elementor Pro version 6.3.313, you are affected.

What should I do right now?

Upgrade to the latest versions of Super Forms and Elementor Pro and review uploaded files for any suspicious activity.

Has this been exploited in the wild?

Yes, both vulnerabilities are reportedly being exploited in the wild.

Sources

Join the 0Day waitlist →

← Back to all threats