Urgent.News

What's breaking now, across thousands of outlets.

Tech

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

We haven't written up this one. The Hacker News has the full story — the link below goes straight to it.

Read the original at thehackernews.com →

More in Tech

Your RLS is on and the table is still readable

A while back I wrote up the pass I run over code an assistant wrote for me: secrets in git history, keys leaking into the client bundle, API routes with no guard, stale dependencies, wildcard CORS.

More from Friday 4 September →