Overview
- Vendors reported that exploitation of the Elementor Pro flaw began on August 19 and that attacks surged in the days after the plugin was patched.
- The Elementor Pro bug lets an attacker submit a file-upload array with an empty first element and a malicious second file, which bypasses validation and writes a .php webshell to wp-content/uploads/elementor/forms/.
- A separate Super Forms vulnerability uses a missing file-type check to deliver Base64-encoded PHP payloads, and Wordfence says combined blocked exploit attempts against both flaws exceed 440,000.
- Site owners should immediately update Elementor Pro to 4.2.2+ and Super Forms to its patched release, scan upload folders for unexpected .php files, and remove any webshells found.
- Defenders must also harden servers and WAFs by blocking PHP execution in upload directories because firewall rules can lag, leaving unpatched sites exposed to account takeover and data theft.