Enterprise IT Support β€’ Bangkok & Nationwide

Technology newsroom

🚨 Urgent Alert! WordPress Users Attacked Over 440,000 Times Via Critical Vulnerabilities in Super Forms and Elementor Pro Plugins

Wordfence detected over 440,000 attacks targeting critical RCE vulnerabilities in popular WordPress plugins Super Forms and Elementor Pro. Users are urged to update immediately to prevent website takeover.

Edited by SyncTech Solution Published Source Original source
🚨 Urgent Alert! WordPress Users Attacked Over 440,000 Times Via Critical Vulnerabilities in Super Forms and Elementor Pro Plugins

πŸ“Œ Key Takeaways:
- Wordfence detected over 440,000 attempted attacks targeting critical security vulnerabilities in two WordPress plugins: Super Forms and Elementor Pro.
- The CVE-2024-2879 vulnerability in Super Forms is rated 9.8 (Critical), allowing unauthenticated attackers to upload malicious files and take over websites.
- The CVE-2023-48777 vulnerability in Elementor Pro is rated 8.8 (High), enabling users with Contributor-level privileges to stealthily upload files for Remote Code Execution (RCE).

Wordfence, a WordPress security company, has released a concerning report, detecting over 440,000 exploit attempts recently. These attacks target high-severity Remote Code Execution (RCE) vulnerabilities in two popular plugins: Super Forms and Elementor Pro, which could lead to complete website control by malicious actors.

🚨 Vulnerability in Super Forms (CVE-2024-2879)
This vulnerability is classified as Critical with a high CVSS score of 9.8. It stems from missing file type validation in Super Forms – Drag & Drop Form Builder plugin versions older than or equal to 9.2.0. This flaw is extremely dangerous because it allows attackers, without needing to log in or possess any system privileges, to upload any file type, including malicious scripts (Web Shells), ultimately leading to website takeover.

⚠️ Vulnerability in Elementor Pro (CVE-2023-48777)
For the popular Elementor Pro plugin, versions older than or equal to 3.11.6 also have a Broken Access Control vulnerability rated High (CVSS 8.8). Unlike Super Forms, this vulnerability requires the attacker to have at least a Contributor-level user account. However, if an attacker gains access to such an account, they can exploit this flaw to upload malicious files and execute remote code, posing a serious threat to website security.

Wordfence strongly advises all WordPress website administrators using these two plugins to urgently check their plugin versions and update to the latest versions immediately to patch these vulnerabilities and prevent potential damage from these attacks. Neglecting this could make your website the next victim.

πŸ’¬ Are your websites using these two plugins? Have you checked and updated them yet?

Let’s build what’s next

Better IT starts with understanding your business.

Tell our engineers what you need and receive an initial recommendation at no cost.