Last seen September 4, 2026

Elementor Pro missing file type validation vulnerability

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

Technical Severity
Medium severity
Lifecycle Status

NEW

What Happened

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

Why This Matters

Publisher reporting describes a security event affecting Over. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.

Recommended Action

Confirm whether Over is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.

Exposure

My Interests Exposure

Exposure unknown

Recommended Response
Last Seen

Sep 04, 2026 14:18

Exposure reason: This incident does not currently match a technology in My Interests.

Exploitation status: ACTIVELY_EXPLOITED

Primary entities:

Amazon AWSWordPressElementor ProSuper FormsSuper Forms – Drag & Drop Form BuilderRemote Code Execution

Authoritative Intelligence

CVE CVE-2026-14894 Incident identifier

EPSS is a vulnerability exploitation probability signal, not proof that your environment is exposed. CISA KEV means known exploitation of the vulnerability, not that your system was exploited.

Public GitHub References

Search GitHub for public repositories that mention this CVE. BugSkan only lists repository metadata as a defensive awareness signal — it does not fetch or display exploit code.

CVE-2026-14894: 2 public repository references found.

shinthink/CVE-2026-14894

Public exploit-related repository

Super Forms Unauthenticated File Upload RCE | CVSS 9.8

1 stars · Python

Open repository
1beelze/CVE-2026-14894

Public GitHub reference

GitHub repository for an AI tooling project

0 stars · Python

Open repository

A public PoC or exploit-related repository means weaponization material may exist in the open. It does not prove your environment was targeted.

Timeline

  • Incident first seen
    Sep 04, 2026 14:18

    BugSkan first recorded this incident.

  • Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
    Sep 04, 2026 14:18

    thehackernews.com · Vulnerability

Sources

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

thehackernews.com · Sep 04, 2026 14:18

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

Open publisher source

Other BugSkan incidents that share identifiers, products, or vendors with this report.

My Interests Match

Want personalized relevance?

Create an account to see which incidents overlap with your interests.

← Back to incident intelligence