Cybersecurity
Wordfence reports exploit attempts against two WordPress plugins
Wordfence said attackers were using two WordPress plugin flaws to upload PHP files, and it reported more than 440,000 blocked exploit attempts across the two issues.
- Wordfence said attackers were targeting flaws in the Super Forms – Drag & Drop Form Builder and Elementor Pro WordPress plugins.
- It said it had blocked more than 250,000 attempts against CVE-2026-14894 and more than 190,000 against CVE-2026-32475.
- Wordfence said attacks against the Super Forms flaw began on 14 July 2026 and reached a peak of more than 40,000 requests on 18 August 2026.
- It said exploitation of CVE-2026-32475 began on 19 August 2026 and depended on a published Elementor page with a Form widget and File Upload field.
- The company advised site owners to patch the plugins, scan for compromise and check for unexpected or recently changed .php files.
Wordfence said attackers were using two file-upload flaws in the Super Forms – Drag & Drop Form Builder and Elementor Pro WordPress plugins. It said both issues let an unauthenticated user upload a PHP file and could lead to remote code execution; the fixes were in versions 6.3.314 and 4.2.2.
For CVE-2026-14894, Wordfence said the attacker sent a POST request to /wp-admin/admin-ajax.php through the super_submit_form endpoint with a Base64-encoded PHP payload and an attacker-chosen filename. It said the uploaded file acted as a PHP web shell called Mushr00w_upl.php.
The company said the Super Forms activity started on 14 July 2026 and reached more than 40,000 requests on 18 August 2026. It listed source addresses including 103.168.147.235, 103.168.146.131, 103.154.152.178, 103.170.97.7, 182.10.130.51, 189.4.122.140, 129.227.46.143, 64.176.209.104, 103.164.182.122 and 37.9.33.62, and said it had blocked more than 250,000 attempts.
For CVE-2026-32475, Wordfence said the attacker submitted the File Upload field as an array with one empty element and a second element carrying a PHP payload. It said exploitation began on 19 August 2026, required a published Elementor page with a Form widget and File Upload field, and had led to more than 190,000 blocked attempts; Patchstack had disclosed details the month before.
Named in this story
Companies
- Wordfence
- said it had blocked exploit attempts and published reports on the attacks
- Patchstack
- disclosed details about CVE-2026-32475 the month before
Products and systems
- Super Forms – Drag & Drop Form Builder
- was the WordPress plugin with the file-upload flaw targeted in the attacks
- Elementor Pro
- was the WordPress plugin with the second file-upload flaw targeted in the attacks
- WordPress
- was the platform running the affected plugins
- Mushr00w_upl.php
- was the PHP web shell uploaded in the Super Forms attacks
How the source tells it
The source was a technical security report in an urgent register, using alarmed language and large attempt counts to stress the scale of the attacks.
- alarm loaded security wording and worst-case consequences were used to frame the flaws
- urgency the piece stressed immediate patching and highlighted ongoing blocked-attempt totals and attack timelines