Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including
Why This Matters
Publisher reporting describes a security event affecting Over. BugSkan could not yet bind a CVE or affected version, so treat the source details as the current record.
Recommended Action
Confirm whether Over is present in your environment, compare your versions against the report, and apply available vendor patches or mitigations.
CVE: CVE-2026-14894
Affected
Amazon AWSWordPressElementor ProSuper FormsSuper Forms – Drag & Drop Form BuilderRemote Code Execution