Two major security flaws are affecting more than six million WordPress websites
- Wordfence discloses two critical flaws in Elementor Pro and Super Forms
- Bugs allow unauthenticated arbitrary file uploads, enabling remote code execution; both patched recently
- Exploitation attempts already exceed 440,000
More than six million WordPress users are at risk of website takeover, researchers have claimed after discovering two major vulnerabilities being exploited in the wild.
Security researchers Wordfence disclosed finding two flaws, one in Elementor Pro, and one in Super Forms - two popular WordPress plugins.
Elementor Pro is a commercial plugin that allows users to build websites using drag-and-drop elements instead of code. With it, they can add advanced widgets, templates, different forms, popups, and more. It is quite a popular solution with more than six million websites actively using it.
Two bugs, hundreds of thousands of attacks
According to Wordfence, up until recently, it was vulnerable to an “unrestricted file type upload” bug in all versions up to,...
Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE