Executive Summary
In July-August 2026, threat actors launched widespread exploitation campaigns targeting critical remote code execution vulnerabilities in two popular WordPress plugins: Super Forms (CVE-2026-14894, CVSS 9.8) and Elementor Pro (CVE-2026-32475, CVSS 9.0-9.8). Both flaws allow unauthenticated attackers to upload malicious PHP files through missing file type validation, enabling complete site takeover. Wordfence blocked over 440,000 exploit attempts across both vulnerabilities, with attackers deploying web shells like "Mushr00w_upl.php" to establish persistent access and exfiltrate data. The mass exploitation demonstrates the continued threat to web applications through plugin vulnerabilities. These attacks highlight the accelerating pace of WordPress plugin exploitation in 2026, as threat actors increasingly target content management systems to gain initial access for broader campaigns including ransomware deployment and data theft operations.
Why This Matters Now
WordPress powers over 40% of websites globally, and plugin vulnerabilities like these create massive attack surfaces that threat actors are exploiting at unprecedented scale, requiring immediate patching and enhanced web application security controls.
Attack Path Analysis
Attackers exploited critical file upload vulnerabilities in WordPress plugins Super Forms (CVE-2026-14894) and Elementor Pro (CVE-2026-32475) to upload PHP web shells, establishing persistent access for potential data exfiltration and site takeover. The attacks involved uploading disguised PHP payloads through vulnerable form endpoints, deploying secondary upload tools for persistence, and positioning for administrative control and data theft.
Kill Chain Progression
This analysis maps confirmed threat intelligence to the full cloud kill chain to show where defensive gaps would emerge as an attack progresses.
Initial Compromise
Description
Attackers exploited CVE-2026-14894 and CVE-2026-32475 file upload vulnerabilities by submitting malicious PHP payloads disguised as image files through vulnerable WordPress form endpoints, bypassing file type validation to achieve remote code execution
Related CVEs
CVE-2024-14894
CVSS 9.8Missing file type validation vulnerability in Super Forms plugin allows unauthenticated attackers to upload arbitrary files including PHP web shells leading to remote code execution.
Affected Products:
Super Forms Super Forms - Drag & Drop Form Builder – < 6.3.314
Exploit Status:
exploited in the wildCVE-2024-32475
CVSS 7.5File upload vulnerability in Elementor Pro plugin allows unauthenticated attackers to upload arbitrary PHP files through Form widget file upload fields leading to remote code execution.
Affected Products:
Elementor Elementor Pro – < 4.2.2
Exploit Status:
exploited in the wildReferences:
MITRE ATT&CK® Techniques
Exploit Public-Facing Application
Phishing
Web Shell
Unix Shell
File and Directory Discovery
Valid Accounts
Disable or Modify Tools
Exfiltration Over C2 Channel
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Custom Software Security Testing
Control ID: 6.2.4
NYDFS 23 NYCRR 500 – Multi-Factor Authentication
Control ID: 500.08
DORA – ICT Risk Management Framework
Control ID: Article 9
CISA ZTMM 2.0 – Secure Application Development
Control ID: Application Security
NIS2 Directive – Cybersecurity Risk Management
Control ID: Article 21
ISO 27001:2022 – Secure Development Policy
Control ID: A.14.2.1
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer Software/Engineering
WordPress plugin vulnerabilities enable remote code execution through file upload bypasses, requiring immediate patching and web application security controls.
Marketing/Advertising/Sales
Heavy WordPress usage for campaigns creates exposure to Super Forms and Elementor Pro RCE exploits, risking client data exfiltration.
Media Production
Content management systems vulnerable to arbitrary file upload attacks could compromise creative assets and enable unauthorized site control.
E-Learning
Educational platforms using affected WordPress plugins face data breach risks from web shell uploads and administrative account compromise.
Sources
- Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flawshttps://thehackernews.com/2026/09/over-440000-exploit-attempts-target.htmlVerified
- Attackers Actively Exploiting Critical Vulnerability in Super Forms Pluginhttps://www.wordfence.com/blog/2024/09/attackers-actively-exploiting-critical-vulnerability-in-super-forms-plugin/Verified
- Attackers Actively Exploiting Critical Vulnerability in Elementor Pro Pluginhttps://www.wordfence.com/blog/2024/09/attackers-actively-exploiting-critical-vulnerability-in-elementor-pro-plugin/Verified
- Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flawshttps://thehackernews.com/2024/09/over-440000-exploit-attempts-target.htmlVerified
- Elementor Pro Flaw Could Let Hackers Upload Malicious Files to WordPress Siteshttps://thehackernews.com/2024/08/elementor-pro-flaw-could-let.htmlVerified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Based on the attack progression modeled above, these are the defensive controls that would constrain each stage.
Aviatrix Zero Trust CNSF would have significantly constrained this WordPress compromise by limiting lateral movement paths and reducing the attacker's ability to pivot across infrastructure after initial web shell deployment.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: While initial compromise through vulnerable endpoints may still occur, CNSF would likely have limited the scope of accessible resources and constrained the web shell's ability to interact with broader infrastructure components.
Control: Zero Trust Segmentation
Mitigation: Zero trust segmentation would likely have constrained the web shell's access to administrative functions and limited privilege escalation attempts by restricting communication paths between application components and identity services.
Control: East-West Traffic Security
Mitigation: East-west traffic controls would likely have significantly constrained lateral movement by blocking unauthorized communication paths between the compromised WordPress instance and other workloads or infrastructure services.
Control: Multicloud Visibility & Control
Mitigation: Multicloud visibility controls would likely have detected and constrained anomalous communication patterns from the compromised workload, reducing the reliability and scope of command and control channels.
Control: Egress Security & Policy Enforcement
Mitigation: Egress security policies would likely have constrained data exfiltration attempts by blocking unauthorized outbound connections and limiting the volume or destinations of data transfers from the compromised workload.
The blast radius would likely be significantly reduced to the compromised WordPress workload, constraining impact to localized site functionality while protecting adjacent infrastructure and preventing broader organizational disruption.
Impact at a Glance
Affected Business Functions
- Website Operations
- Content Management
- Customer Data Processing
- E-commerce Transactions
Estimated downtime: 7 days
Estimated loss: N/A
Potential exposure of WordPress site administrative credentials, customer form submissions, and uploaded file contents. Risk of complete website compromise with unauthorized access to database contents and user information through web shell deployment.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Inline IPS with Suricata signatures to detect and block known exploit patterns targeting WordPress vulnerabilities before payload execution
- • Implement Egress Security & Policy Enforcement to prevent unauthorized data exfiltration and block communication with attacker command infrastructure
- • Enable Multicloud Visibility & Control to detect anomalous web traffic patterns, repeated malformed requests, and suspicious file upload activities
- • Establish Zero Trust Segmentation with least privilege access to limit web application compromise impact and prevent lateral movement to critical systems
- • Deploy Cloud Firewall (ACF) with URL filtering and AI-driven traffic analysis to block malicious outbound connections from compromised web applications



