Severe Elementor Pro and Super Forms Vulnerabilities Threaten More Than Six Million WordPress Sites
Wordfence, a security company, cautions that two critical flaws in the Elementor Pro page‑builder and the Super Forms plugin put over six million WordPress sites at risk of remote code execution.
Both vulnerabilities rely on the same exploit path: they permit any internet user to upload a file to an unprotected site without needing credentials. After the malicious file lands on the server, the attacker can run arbitrary code and possibly seize complete control of the site.
Since the issues were disclosed, Wordfence’s sensors have recorded more than 440,000 attempts to exploit the bugs. This traffic volume indicates that malicious actors are actively probing for unpatched installations, using the unauthenticated upload shortcut to launch automated attacks at scale.
The developers of both plugins acted swiftly, releasing updates that seal the upload routes and reinforce input validation. Wordfence’s advisory recommends that site operators upgrade to the newest releases without delay and confirm the patches are in place, since earlier versions stay vulnerable.
Approximately 40% of all publicly accessible websites run on WordPress, whose modular design depends heavily on third‑party plugins. This adaptability fuels its popularity but also expands the attack surface; widely used add‑ons such as Elementor Pro and Super Forms run on millions of sites, drawing the interest of cyber‑criminals.
Specialists advise administrators to not only install the updates but also audit server logs for evidence of illicit file uploads, enforce strict file‑type policies, and contemplate extra hardening steps like web‑application firewalls. As the platform evolves, continuous vigilance and prompt patching stay the best protection against comparable dangers.
Comments (0)
Be the first to comment.
Join the discussion