Particle.news

Critical Elementor Pro and Super Forms Flaws Under Heavy Exploitation

Security firms say widespread probe activity can upload PHP webshells that let attackers run code and seize WordPress sites.

Overview

  • Vendors reported that exploitation of the Elementor Pro flaw began on August 19 and that attacks surged in the days after the plugin was patched.
  • The Elementor Pro bug lets an attacker submit a file-upload array with an empty first element and a malicious second file, which bypasses validation and writes a .php webshell to wp-content/uploads/elementor/forms/.
  • A separate Super Forms vulnerability uses a missing file-type check to deliver Base64-encoded PHP payloads, and Wordfence says combined blocked exploit attempts against both flaws exceed 440,000.
  • Site owners should immediately update Elementor Pro to 4.2.2+ and Super Forms to its patched release, scan upload folders for unexpected .php files, and remove any webshells found.
  • Defenders must also harden servers and WAFs by blocking PHP execution in upload directories because firewall rules can lag, leaving unpatched sites exposed to account takeover and data theft.