September 6, 2026
- More than 440,000 exploit attempts collectively targeted Elementor Pro and Super Forms flaws. The count covers CVE-2026-32475 in Elementor Pro and CVE-2026-14894 in Super Forms, rather than Elementor alone. The Hacker News reports the volume, and SecurityWeek confirms Elementor exploitation. A public lab has also shipped since the initial warning (earlier coverage). · Vulnerabilities & Exploits
- A CVE-2026-32475 lab reproduces Elementor Pro’s unauthenticated file-upload-to-RCE path. The controlled environment covers the reported validation and file-move desynchronization and can support exposure validation and detection development. GitHub · New Tools & Releases