• Two major security flaws are affecting more than six million Word

    From TechnologyDaily@1337:1/100 to All on Mon Sep 7 19:00:21 2026
    Two major security flaws are affecting more than six million WordPress websites

    Date:
    Mon, 07 Sep 2026 17:45:00 +0000

    Description:
    Patches are available, so WordPress users should hurry up and apply them.

    FULL STORY ======================================================================Copy link Facebook X Whatsapp Reddit Pinterest Flipboard Threads Email Share this article 0 Join the conversation Follow us Add us as a preferred source on Google Newsletter Subscribe to our newsletter Wordfence discloses two
    critical flaws in Elementor Pro and Super Forms Bugs allow unauthenticated arbitrary file uploads, enabling remote code execution; both patched recently Exploitation attempts already exceed 440,000 More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild.

    Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms - two popular WordPress plugins . Elementor Pro
    is a commercial plugin that allows users to build websites using
    drag-and-drop elements instead of code. With it, they can add advanced widgets, templates, different forms, popups, and more. It is quite a popular solution with more than six million websites actively using it. Latest Videos From TechRadar Watch full video here: Two bugs, hundreds of thousands of attacks According to Wordfence, up until recently, it was vulnerable to an unrestricted file type upload bug in all versions up to, and including,
    4.2.1. This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible, the researchers explained. This requires that the targeted site has published a page containing an Elementor Pro Form widget with at least one non-required File Upload field.

    The bug is tracked as CVE-2026-32475, carries a severity score of 9.8/10 (critical), and was patched in mid-August 2026. So far, Wordfence alone blocked more than 190,000 exploit attempts. You may like Experts warn
    millions of WordPress websites could be at risk following reveal of worrying bugs Over 1 million WordPress sites at risk after popular plugins hacked Experts warn 2,000 hacked WordPress sites were secretly running a global
    crime ring

    At roughly the same time, the researchers also reported finding a flaw in Super Forms, a form builder plugin that lets users create and manage forms using a drag-and-drop interface. This plugin, with some 13,000 active installations, contained a bug that allowed arbitrary file upload in all versions up to, and including, 6.3.313.

    This makes it possible for unauthenticated attackers to upload files that may be executable, which makes remote code execution possible, the researchers explained. Are you a pro? Subscribe to our newsletter Sign up to the
    TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed! Contact me with news and offers from other Future brands Receive email from us on behalf of our trusted partners
    or sponsors By submitting your information you agree to the Terms &
    Conditions and Privacy Policy and are aged 16 or over.

    This one is tracked as CVE-2026-14894, also carries a severity score of
    9.8/10 (critical) and it, too, was patched a few weeks ago. For this flaw, Wordfence observed more than 250,000 exploitation attempts meaning that cumulatively, these two resulted in 440,000 attacks already.

    Given the widespread adoption of these plugins, and the fact that the flaws are being actively leveraged, users are advised to apply the fixes without delay.

    Via The Hacker News The best antivirus for all budgets Our top picks, based on real-world testing and comparisons

    Read our full guide to the best antivirus 1. Best overall: Bitdefender Total Security 2. Best for families: Norton 360 with LifeLock 3. Best for mobile: McAfee Mobile Security Follow TechRadar on Google News and add us as a preferred source to get our expert news, reviews, and opinion in your feeds.



    ======================================================================
    Link to news story: https://www.techradar.com/pro/security/two-major-security-flaws-are-affecting- more-than-six-million-wordpress-websites


    --- Mystic BBS v1.12 A49 (Linux/64)
    * Origin: tqwNet Technology News (1337:1/100)