Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Summary

Threat actors are actively exploiting two critical vulnerabilities in popular WordPress plugins, Super Forms and Elementor Pro. One vulnerability in Super Forms, a missing file type validation flaw, allows unauthenticated attackers to upload arbitrary files with a CVSS score of 9.8.

IFF Assessment

FOE

This article highlights active exploitation of critical vulnerabilities, posing a direct threat to websites and their data, which is bad news for defenders.

Severity

9.8 Critical

Defender Context

Defenders should prioritize patching or mitigating these vulnerabilities in Super Forms and Elementor Pro installations immediately. The high CVSS score and active exploitation indicate a significant risk of compromise, potentially leading to further attacks or data breaches.

Read Full Story →