Critical Flaws in Super Forms and Elementor Pro Under Active Attack
- Severity
- CRITICAL
- CVSS
- 9.8
- Affected component
- super-forms (wordpress)
- Affected versions
- >= v6.3.313, <= v6.3.313
- Patched version
- Not yet available
Threat actors are reportedly exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, allowing unauthenticated file uploads and potential remote code execution.
What happened
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro. CVE-2026-14894 in Super Forms allows unauthenticated attackers to upload files of any type, including executable PHP files, leading to remote code execution. Similarly, CVE-2026-32475 in Elementor Pro enables unauthenticated file uploads, which can result in remote code execution. These vulnerabilities can be leveraged to write a PHP web shell to the site and execute arbitrary code, potentially leading to the creation of administrator accounts, data exfiltration, or complete site takeover.
Super Forms versions affected range from 6.3.313 to 6.3.313, while Elementor Pro versions affected range from 6.3.313 to 6.3.313. It is crucial for users of these plugins to upgrade to the latest versions to mitigate the risk of exploitation.
What to do about it
- Upgrade Super Forms to version 6.3.314 or later.
- Upgrade Elementor Pro to version 4.2.2 or later.
- Review uploaded files for any suspicious activity.
- Monitor the primary sources for updates on the vulnerabilities and any additional mitigation steps.
How 0Day would have caught this
super-forms is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.
Frequently asked questions
Am I affected?
If you are using Super Forms version 6.3.313 or Elementor Pro version 6.3.313, you are affected.
What should I do right now?
Upgrade to the latest versions of Super Forms and Elementor Pro and review uploaded files for any suspicious activity.
Has this been exploited in the wild?
Yes, both vulnerabilities are reportedly being exploited in the wild.