440,000+ Attacks Target Critical WordPress Plugin Flaws — Is Your Site at Risk?
Security researchers at Wordfence have detected more than 440,000 exploitation attempts targeting two critical vulnerabilities in widely used WordPress plugins: Super Forms – Drag & Drop Form Builder and Elementor Pro. The most severe flaw, CVE-2026-14894, carries a near-maximum severity score of 9.8 out of 10 and stems from a missing file type validation check in Super Forms. This flaw lets attackers upload malicious files to a website without needing to log in, potentially handing them full control of the affected server.
Because these plugins are used by hundreds of thousands of small business websites, the scale of the attack campaign is significant. Unauthenticated remote code execution flaws like this one are especially dangerous because attackers don't need stolen credentials or insider access — they can exploit the vulnerability directly from the internet. Once exploited, attackers could deface websites, steal customer data, install ransomware, or use the compromised site as a launchpad for further attacks.
For Australian small businesses running WordPress sites, this is a timely reminder that plugins are often the weakest link in website security. Even a well-maintained WordPress core installation can be compromised through an outdated or vulnerable plugin, and attackers are actively scanning the internet for exposed, unpatched sites right now.