ARTIFICE DAILY AI + CYBER SECURITY BRIEFING

Cybersecurity

Wordfence reports exploit attempts against two WordPress plugins

Wordfence said attackers were using two WordPress plugin flaws to upload PHP files, and it reported more than 440,000 blocked exploit attempts across the two issues.

The Hacker News

Wordfence said attackers were using two file-upload flaws in the Super Forms – Drag & Drop Form Builder and Elementor Pro WordPress plugins. It said both issues let an unauthenticated user upload a PHP file and could lead to remote code execution; the fixes were in versions 6.3.314 and 4.2.2.

For CVE-2026-14894, Wordfence said the attacker sent a POST request to /wp-admin/admin-ajax.php through the super_submit_form endpoint with a Base64-encoded PHP payload and an attacker-chosen filename. It said the uploaded file acted as a PHP web shell called Mushr00w_upl.php.

The company said the Super Forms activity started on 14 July 2026 and reached more than 40,000 requests on 18 August 2026. It listed source addresses including 103.168.147.235, 103.168.146.131, 103.154.152.178, 103.170.97.7, 182.10.130.51, 189.4.122.140, 129.227.46.143, 64.176.209.104, 103.164.182.122 and 37.9.33.62, and said it had blocked more than 250,000 attempts.

For CVE-2026-32475, Wordfence said the attacker submitted the File Upload field as an array with one empty element and a second element carrying a PHP payload. It said exploitation began on 19 August 2026, required a published Elementor page with a Form widget and File Upload field, and had led to more than 190,000 blocked attempts; Patchstack had disclosed details the month before.

Named in this story

Companies

Wordfence
said it had blocked exploit attempts and published reports on the attacks
Patchstack
disclosed details about CVE-2026-32475 the month before

Products and systems

Super Forms – Drag & Drop Form Builder
was the WordPress plugin with the file-upload flaw targeted in the attacks
Elementor Pro
was the WordPress plugin with the second file-upload flaw targeted in the attacks
WordPress
was the platform running the affected plugins
Mushr00w_upl.php
was the PHP web shell uploaded in the Super Forms attacks

How the source tells it

The source was a technical security report in an urgent register, using alarmed language and large attempt counts to stress the scale of the attacks.

  • alarm loaded security wording and worst-case consequences were used to frame the flaws
  • urgency the piece stressed immediate patching and highlighted ongoing blocked-attempt totals and attack timelines