Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence.The vulnerabilities in question are – CVE-2026-14894 (CVSS score: 9.8) – A missing file type validation vulnerability in Super Forms Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including
First seen on thehackernews.com
Jump to article: thehackernews.com/2026/09/over-440000-exploit-attempts-target.html
![]()

