Critical Elementor Pro and Super Forms Flaws Put Over Six Million WordPress Sites at Risk
Security firm Wordfence has warned that two high‑severity vulnerabilities in the Elementor Pro page‑builder and the Super Forms plugin expose more than six million WordPress websites to remote code execution attacks.
The bugs share a common attack vector: they allow anyone on the internet to upload a file to a vulnerable site without authentication. Once the malicious file is placed on the server, an attacker can execute arbitrary code, potentially taking full control of the compromised site.
Since the disclosures were made, Wordfence’s monitoring tools have logged over 440,000 exploitation attempts targeting the flaws. The volume of traffic suggests that threat actors are actively scanning for sites that have not yet applied the fixes, leveraging the ease of unauthenticated uploads to automate attacks at scale.
Both plugin developers responded quickly, publishing patches that close the upload pathways and tighten input validation. Wordfence’s advisory urges site owners to update to the latest versions immediately and to verify that the patches have been applied, as older releases remain vulnerable.
WordPress powers roughly 40% of all websites on the public internet, and its extensible architecture relies heavily on third‑party plugins. While this flexibility drives adoption, it also creates a large attack surface; popular extensions like Elementor Pro and Super Forms are installed on millions of sites, making them attractive targets for cyber‑criminals.
Experts recommend that administrators not only apply the updates but also review server logs for any signs of unauthorized file uploads, enforce strong file‑type restrictions, and consider additional hardening measures such as web‑application firewalls. As the ecosystem continues to evolve, vigilance and timely patch management remain the most effective defenses against similar threats.
Comments (0)
Be the first to comment.
Join the discussion