Active campaign exploits Super Forms and Elementor Pro failures to upload and run PHP

Author: Published 5 min de lectura 14 reading

The images in this article were generated with artificial intelligence. How we publish

Security researchers have documented an active campaign that takes advantage of two critical failures in popular WordPress supplements to upload arbitrary files and run code on vulnerable sites. The vulnerabilities are CVE-2026-14894 in Super Forms (CVSS 9.8) and CVE-2026-32475 in Elementor Pro (CVSS 9.0 / 9.8)., both corrected in versions published by their maintainers (Super Forms: 6.3.314; Elementor Pro: 4.2.2). Wordfence reports indicate hundreds of thousands of attempts at exploitation and sustained activity from mid-July and August 2026.

From a technical point of view, the vector is a classic file type validation failure in the form upload component. In the case observed against Super Forms, attackers send a POST request to / wp-admin / admin-ajax.php using the plugin endpoint and inject into the file field an URI data chain with prefix "data: image / gif; base64," which hides a PHP payload encoded in Base64. The specific structure of the shipment - an arrangement where the first element is empty and the second one contains the file with name ending in .php - seems to be the sequence that triggers the bypass of the verification. The resulting file (documented as Mushr00w _ upl.php in analyzed cases) is written in the file system, usually low / wp-content / uploads / element / forms / with a random name but retaining the .php extension, and can be invoked directly to run commands on the server.

Active campaign exploits Super Forms and Elementor Pro failures to upload and run PHP
Image generated with IA.

In the case of Elementor Pro, the operation requires that the site have at least one page published with a Form widget that includes a File Upload field; if that condition is met, the same technique allows you to upload and run code. Wordfence records that attempts against CVE-2026-14894 began on July 14, 2026 and reached a peak of more than 40,000 requests per day on August 18; the offensives taking advantage of CVE-2026-32475 began on August 19. The company has blocked over 250,000 and 190,000 attempts respectively, figures that confirm the scale of abuse.

Facts confirmed: There are two vulnerabilities identified by CVE, both with published corrections; Wordfence has recorded and blocked large volumes of exploitative attempts; attackers use URis data with PHP payloads and manage to write .php accessible files in uploads directories. To expand technical information and official vulnerability inputs, the NVD pages are available: CVE-2026-14894 and CVE-2026-32475, and public communications from the services that have reported it, such as Wordfence and Patchstack ( Wordfence, Patchstack).

Impact and capabilities of the attacker: Once a PHP file is stored and can be run, the attacker has an input door (web shell) to run commands on the web server. With that access it is possible to install persistence, create or promote administrative accounts in WordPress, exfilter databases and files, install additional malware or take full control of the site and, potentially, the server. In shared or poorly configured facilities, the intrusion can be extended to other sites housed on the same machine.

Attempts have left multiple IP addresses, some documented by the analysers; public examples include 103.168.147.235, 103.170.97.7, 129.227.46.143 and 185.196.220.85, among others. These lists change quickly and do not on their own guarantee that a site is committed, but serve as indicators of the observed campaign.

What a WordPress site owner should do right now (concrete steps): in this order and without delay:

1) Immediately update Super Forms and Elementor / Elementor Pro to the versions that correct these faults (Super Forms ≥ 6.3.314; Elementor Pro ≥ 4.2.2). If you cannot apply the update immediately, temporarily disable form widgets with file uploading or vulnerable plugin.

2) Review the uploads directory for unexpected PHP files. Useful searches (run on the WordPress root with SSH access) include locating .php files within wp-content / uploads or specifically in wp-content / uploads / elementor / forms. Examples of checks: search .php files with recent modification dates or foreign names, and review permissions and owners.

3) Scanning the site with malware detection tools (Wordfence, MalCare, Sucuri) and reviewing web access logs for requests to newly created files or / wp-content / uploads / element / forms / * .php. Check suspicious admin activity (user creation, plugin changes and themes).

4) If you find a web shell or remote running evidence, isolate the installation: put the site in maintenance mode, change passwords (WP users and FTP / SSH accounts), revoke API credentials, and consider restoring from a clean backup prior to the commitment date. Do not assume that a surface cleaning eliminates all back doors: audite cron jobs, wp-config.php and plugins / modified themes.

5) Server-level tipping: disable PHP execution in wp-content / uploads (e.g. with a rule in html access or vhost configuration that denies php _ handler in those directories), limit file permissions, and apply WAF / ModSecurity rules that block uploads with URis data or charges that include suspicious chains. Set up white lists of MIME types when possible.

Active campaign exploits Super Forms and Elementor Pro failures to upload and run PHP
Image generated with IA.

6) Continuous monitoring and prevention: implement file integrity alerts, keep backup outside the main hosting, and consider managed detection solutions if the site supports traffic or sensitive assets.

Information still uncertain and reasonable estimates: not all blocked attempts involve successful commitments; Wordfence reports the scale of attacks but the public success rate has not been detailed. It is also not clear how many sites have been completely taken by the campaign against those where the attempt was detected and mitigated in time. Also, attackers often rotate infrastructure and payloads, so new variants could appear.

In short: the threat is real, exploitable remotely and is being actively abused. The recommended immediate intervention is to update the affected plugins and audit any file uploading element on your site. If you detect anomalies and do not have the technical staff for full remediation, hire a specialized incident response team before restoring the normal operation.

Coverage

Related

More news on the same subject.