Two of WordPress's most popular plugins shipped critical, unauthenticated file-upload bugs, and attackers found them first.
Security firm Wordfence disclosed a critical flaw in Elementor Pro, the drag-and-drop site builder used on more than six million WordPress sites, and a second in Super Forms, a smaller form-building plugin with about 13,000 installs. Both bugs, tracked as CVE-2026-32475 and CVE-2026-14894, let unauthenticated attackers upload executable files and score 9.8 out of 10 on the severity scale. The Elementor Pro bug only triggers on pages using a Pro Form widget with an optional file-upload field, which narrows but does not eliminate the exposure given the plugin's install base. Both vendors shipped patches in mid-August 2026, weeks before this disclosure went public.
Wordfence has already logged more than 440,000 exploit attempts across the two flaws, meaning the gap between patch and adoption is where the real damage happens. Elementor Pro's scale is the real story. A bug this severe in a plugin installed on six million sites turns a niche vulnerability into an internet-wide problem the moment proof-of-concept code spreads.
WordPress's plugin ecosystem keeps producing the same pattern: patch first, panic later. File-upload bugs remain one of the most reliable paths to a full site takeover.