למעלה מ-440,000 ניסיונות תקיפה נגד חורי RCE ב-Super Forms ו-Elementor Pro
Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

◆ סיכום AI
דיווחים מצביעים על ניסיונות ניצול נרחבים של פגיעויות קריטיות בתוספי וורדפרס פופולריים: Super Forms ו-Elementor Pro. פגיעות Super Forms, המסומנת כ-CVE-2026-14894, מאפשרת העלאת קבצים מכל סוג על ידי תוקפים לא מאומתים, בעוד שפגיעות Elementor Pro מאפשרת ביצוע קוד מרחוק (RCE). מתקפות אלו מדגישות את החשיבות הקריטית של עדכוני אבטחה שוטפים ביישומי ווב.
# מהמקור
Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including