Two major security flaws are affecting more than six million WordPress websites
Patches are available, so WordPress users should hurry up and apply them.
Two critical vulnerabilities have been discovered in two popular WordPress plugins, Elementor Pro and Super Forms, affecting over six million websites. Wordfence, a security firm, disclosed the flaws which enable unauthenticated attackers to upload and execute arbitrary files, potentially leading to remote code execution. Both vulnerabilities allow exploitation attempts, exceeding 440,000 already, yet both were patched recently.
The first bug, CVE-2026-32475, was found in Elementor Pro and the second, CVE-2026-14894, was identified in Super Forms. Both have a severity score of 9.8/10, classified as critical. Wordfence alone blocked over 190,000 exploit attempts for Elementor Pro and more than 250,000 for Super Forms. Experts recommend users to apply the fixes immediately due to the widespread use of these plugins and the active exploitation of these vulnerabilities.
Written by urgent.news from TechRadar's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.