CuraSec

Act active

440K Exploit Attempts Hit Super Forms & Elementor Pro RCE Flaws

2026-09-04 14:56 UTC · The Hacker News · read the source ↗ #wordpress#rce#active-exploitation
  • Engineer — Act: Active campaign with public PoC and 440k observed attempts makes this urgent despite low EPSS — if you run Super Forms or Elementor Pro on any WordPress site, update both plugins immediately and audit web-accessible upload directories for dropped files.
  • SOC/IR — Act: The scale of this campaign (440k attempts) warrants sweeping web server logs for unauthenticated POST requests to Super Forms and Elementor Pro upload endpoints, and hunting for newly created PHP files in WordPress upload paths since the PoC became public.
  • Leader — Plan: Confirm whether WordPress with these plugins exists in any customer-facing or internal properties; if so, ensure the patch-and-audit cycle is assigned and tracked — the exploitation volume makes this a realistic exposure risk worth validating this week.
  • Signals: CVE-2026-14894 — CISA KEV: not listed, EPSS 0.05, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment (CISA KEV / EPSS / public PoC). Verify against the original source before acting. Found a bad verdict? Report it — confirmed errors go to the corrections log.