Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Summary
Threat actors are actively exploiting two critical vulnerabilities in popular WordPress plugins, Super Forms and Elementor Pro. One vulnerability in Super Forms, a missing file type validation flaw, allows unauthenticated attackers to upload arbitrary files with a CVSS score of 9.8.
IFF Assessment
FOE
This article highlights active exploitation of critical vulnerabilities, posing a direct threat to websites and their data, which is bad news for defenders.
Severity
9.8
Critical
Defender Context
Defenders should prioritize patching or mitigating these vulnerabilities in Super Forms and Elementor Pro installations immediately. The high CVSS score and active exploitation indicate a significant risk of compromise, potentially leading to further attacks or data breaches.