Affected Systems

Super Forms – Drag & Drop Form Builder (all versions prior to 6.3.314) and Elementor Pro (all versions prior to 4.2.2). Over 440,000 exploit attempts detected. CVE-2026-14894 affects all Super Forms installations; CVE-2026-32475 requires at least one published Elementor page with Form widget containing File Upload field.

Exploitation Status

Active exploitation confirmed since July 14, 2026 (CVE-2026-14894) and August 19, 2026 (CVE-2026-32475). Wordfence blocked over 250,000 attempts against Super Forms and 190,000 against Elementor Pro. Attackers deploying PHP web shells (e.g., "Mushr00w_upl.php") to achieve remote code execution. Multiple attacker IP addresses identified.

Business Impact

Unauthenticated attackers can upload arbitrary PHP files and execute remote code on vulnerable WordPress sites. Successful exploitation enables creation of rogue administrator accounts, data exfiltration, and full site takeover. Both vulnerabilities scored CVSS 9.0-9.8 (Critical). Organizations running affected plugins face immediate risk of compromise with no authentication barrier.

Urgency

🔴 Immediate

Recommended Actions

  • Update Super Forms to version 6.3.314 or later immediately
  • Update Elementor Pro to version 4.2.2 or later immediately
  • Scan WordPress uploads directories (/wp-content/uploads/elementor/forms/ and Super Forms upload paths) for unexpected .php files created since July 14, 2026
  • Review WordPress user accounts for unauthorized administrator-level accounts created recently
  • Block known attacker IPs at firewall/WAF: 103.168.147.235, 103.168.146.131, 103.154.152.178, 103.170.97.7, 182.10.130.51, 189.4.122.140, 129.227.46.143, 64.176.209.104, 103.164.182.122, 37.9.33.62, 185.196.220.85, 103.84.230.85, 103.90.148.202, 216.126.225.208, 167.254.240.75, 167.254.241.119, 114.10.17.253, 114.10.45.151
  • Monitor web server logs for POST requests to /wp-admin/admin-ajax.php with 'super_submit_form' action or suspicious form submissions to Elementor forms