In September, Wordfence reported active attacks on three file upload flaws in WordPress plugins: Elementor Pro, Super Forms and Wholesale Lead Capture for WooCommerce. Each one lets a visitor with no account send a PHP file through a public form and have the server keep it. All three are patched. Wordfence’s firewall counts add up to over 540,000 blocked exploit attempts across the three. It published its reports between September 2 and September 14, 2026.
This piece walks through each flaw, the version that fixes it, and what the security firms published. It then covers how an agency finds the affected plugins across a client portfolio, what order to update in, and what to check afterward. A fourth plugin, All-in-One WP Migration, showed up in some September coverage. Its flaw is not one of the file upload flaws, and exploitation had not been confirmed as of September 27.
The short version: update Elementor Pro to 4.2.2, Super Forms to 6.3.314 and Wholesale Lead Capture to 2.0.3.2. Then look for PHP files in the uploads folder. Updating closes the hole, but it does not remove a file an attacker already placed.
What the three file upload flaws have in common
The pattern is the same in all three. A form accepts a file from an anonymous visitor. The plugin fails to check the file type properly. The file lands inside wp-content/uploads, and if the web server runs PHP from that folder, the attacker has a web shell.
None of the three file upload flaws needs a login. Each is rated critical by the firm that scored it. The requests all go to /wp-admin/admin-ajax.php, the standard WordPress endpoint for background form handling, which is why log review works the same way for each one.
What differs is reach. Elementor Pro sits on millions of sites. Super Forms and Wholesale Lead Capture are niche. For an agency, the practical question about these file upload flaws is which clients run which plugin, and whether any of them had a public upload field live while unpatched.
| Plugin | CVE and fixed version | Login needed | Attempts blocked (per Wordfence) |
|---|---|---|---|
| Elementor Pro | CVE-2026-32475, 4.2.2 | None | Over 190,000 |
| Super Forms | CVE-2026-14894, 6.3.314 | None | Over 250,000 |
| Wholesale Lead Capture | CVE-2026-27540, 2.0.3.2 | None | Over 100,000 |
The counts are Wordfence’s own firewall numbers. They measure blocked attempts on sites Wordfence protects, not successful compromises.
Elementor Pro 4.2.2: the widest reach of the three
CVE-2026-32475 affects Elementor Pro 4.2.1 and earlier. Of the three file upload flaws, it reaches the most sites. Patchstack, which found and disclosed it, published its technical write-up on August 19, 2026, the same day Elementor shipped 4.2.2. Patchstack credits researcher Tin Pham, who reported it on July 16.
The bug sits in the Form widget’s File Upload field. According to Patchstack, the plugin checks uploaded files in one loop and moves them in another. The two loops handle an empty entry differently. An attacker sends an empty file followed by a PHP file, the check skips the second one, and the move step saves it anyway. Patchstack says the file is written to wp-content/uploads/elementor/forms/ with a random name ending in .php.
Wordfence published its exploitation report on September 2. It says attacks began "the same day the vulnerability was disclosed," and that its firewall "has blocked over 190,000 exploit attempts since the vulnerability was publicly disclosed." Wordfence lists Elementor Pro at more than 6 million active installations.
Which Elementor Pro sites are exposed
The sources do not fully agree here. Patchstack says the only requirement is a published page with a Form widget that includes a File Upload field. Wordfence says the field must be non-required. Elementor, in a statement reported by BleepingComputer, said only sites with the multiple file upload option enabled are affected, and that the option is off by default.
We could not reach Elementor’s own statement to confirm the wording. For triage, treat any Elementor Pro form with an upload field as exposed until you check its settings. Update every Elementor Pro site regardless; Elementor itself recommends that.
The score also differs by firm. Patchstack and the NVD record rate it 9.0. Wordfence rates it 9.8. Both are critical.
Super Forms 6.3.314: two requests to a web shell
CVE-2026-14894 affects Super Forms, a drag-and-drop form builder, in all versions up to 6.3.313. The NVD record, sourced from Wordfence, describes missing file type validation in the plugin’s submit_form function. The only barrier is a session nonce that an anonymous visitor can request from a separate public endpoint.
In plain terms, the attacker asks the site for a token, then uses it to upload a PHP file. It is the simplest of September’s file upload flaws. Wordfence’s report describes it as two unauthenticated HTTP requests.
The developer’s fix on GitHub is labeled "Security: harden form file-upload handling (CVE-2026-14894); v6.3.314." Wordfence says the vendor released the patched version on July 8, 2026, and that Wordfence disclosed the flaw on July 9. The Patchstack database entry lists the same affected and fixed versions.
Wordfence’s September 3 report says its firewall "has already blocked over 250,000 exploit attempts targeting this vulnerability." That is a large number for a plugin Wordfence estimates at 13,000 active installations. Mass scanning hits every site, not just the ones running the plugin.
Wordfence names one dropped file, Mushr00w_upl.php, a small uploader used to stage more files. It notes attackers may use other names.
Wholesale Lead Capture 2.0.3.2: patched in February, attacked since June
CVE-2026-27540 affects Wholesale Lead Capture for WooCommerce, a premium plugin from Rymera (sold as part of Wholesale Suite), in versions up to 2.0.3.1. The CVE record, assigned by Patchstack, lists 2.0.3.2 as the fix. Patchstack’s database entry dates the disclosure to February 20, 2026, and credits researcher Teemu Saarentaus.
Of the three file upload flaws, this is the one agencies are most likely to have missed. The patch is seven months old. Wordfence’s September 14 report says its firewall "has already blocked over 100,000 exploit attempts" with heavy activity "between June 4th and June 17th, and also on July 1st and August 30th." In other words, attacks were running for months before the press picked it up.
The upload goes through an AJAX action named wwlc_file_upload_handler. Wordfence reports attackers uploading a file named shell.php. It estimates the plugin at about 6,000 active installations.
Any client that runs WooCommerce with a wholesale registration form should be checked for it.
Where All-in-One WP Migration fits, and where it does not
All-in-One WP Migration and Backup appeared in some September roundups next to these three. It does not belong in the same bucket.
CVE-2026-19949 is a second-order SQL injection, not a file upload flaw. The CVE record, assigned by Wordfence, covers versions through 7.109 and rates it 8.8. The fix shipped in 7.110. According to the record, the injected data fires during an archive restore and can expose a secret key that leads to code execution. BleepingComputer reported that the payload waits until an administrator restores a backup.
Exploitation was not confirmed by a named security firm as of September 27. One trade outlet cited SOCRadar listing a public proof of concept, with SOCRadar noting no independent confirmation of attacks.
WPScan’s listing also shows two newer issues fixed in 7.111, published September 16. With millions of installs, the plugin is common on agency sites. Update it to 7.111 or later, but it is not the emergency the three file upload flaws are.
Finding client sites exposed to the file upload flaws
Start with an inventory of which sites carry the file upload flaws. If you manage sites over SSH, WP-CLI’s plugin list command reports each plugin’s name, status and version.
wp plugin list --fields=name,status,version --format=csv
The command filters on any field, so you can ask for one plugin at a time:
wp plugin list --name=elementor-pro --fields=name,status,version
To run that across a portfolio, WP-CLI supports aliases and alias groups in wp-cli.yml. The handbook’s guide to running commands remotely shows a group that points one command at several sites. Define a group for your clients and run the list once.
Slugs to search for, based on the vendor and database records:
- elementor-pro: Elementor Pro. Safe at 4.2.2 or later.
- super-forms: Super Forms. Safe at 6.3.314 or later.
- woocommerce-wholesale-lead-capture: Wholesale Lead Capture. Safe at 2.0.3.2 or later.
- all-in-one-wp-migration: All-in-One WP Migration. Update to 7.111 or later.
Check the folder name on a real site before you script it. A renamed or bundled copy will not match.
Include inactive plugins in the search. An inactive plugin cannot run, but it will run again the day someone reactivates it.
If a client sits on managed hosting without SSH, use the host’s dashboard. Many managed hosts show plugin versions per site, and some flag known vulnerable versions. Our managed WordPress host buying framework covers what to expect from that layer.
Update order for an agency portfolio
Sort by exposure, not by client size.
- Sites with a public upload field on a vulnerable version. Elementor Pro forms with a File Upload field, any Super Forms form with uploads, and any Wholesale Lead Capture registration form. Update these first and check them for dropped files the same day.
- Wholesale Lead Capture on anything before 2.0.3.2. The patch has been out since February and attacks have run since June. Treat these sites as possibly compromised.
- Remaining Elementor Pro and Super Forms installs. Update even when no upload field exists today. A content editor can add one tomorrow.
- All-in-One WP Migration. Move to 7.111 or later on the normal schedule.
Two of the three are premium plugins. Elementor Pro and Wholesale Lead Capture typically update through a vendor license, so a lapsed license can block the update. Confirm the installed version after updating rather than trusting the update screen.
What to look for after updating
The security firms describe specific signs. Wordfence says the Elementor Pro forms folder should hold only form submissions, and that "the presence of any .php file in this location is a strong indicator of compromise." Patchstack advises reviewing wp-content/uploads/elementor/forms/ for any file that is not a type the forms actually accept.
For Super Forms, Wordfence advises checking for unexpected or recently modified .php files created after July 8, 2026. For Wholesale Lead Capture, it points to unexpected .php files in the uploads directory. A quick check on each site:
find wp-content/uploads -type f -name "*.php"
Some plugins leave a blank index.php in their upload folders, so compare hits against what each plugin normally writes. Anything else deserves a close look.
Next, read the access logs. Wordfence lists the AJAX actions tied to each attack:
- Elementor Pro: requests to
admin-ajax.phpwithelementor_pro_forms_send_form. - Super Forms: requests with the
super_submit_formaction. - Wholesale Lead Capture: requests with the
wwlc_file_upload_handleraction.
A form submission on its own proves nothing. A submission followed by requests to a new .php path in uploads does.
Then check accounts. Wordfence’s Super Forms report tells affected owners to remove any unknown administrator accounts and unexpected files. List administrators with their registration dates:
wp user list --role=administrator --fields=ID,user_login,user_registered
Look for accounts created during the exposure window that no one on the client side recognizes.
Hardening the sources point to
The advice from Wordfence and Patchstack comes down to four things. Update, review uploads for file types the forms should not accept, review logs for the listed actions, and remove unknown admins and files.
The server layer matters for all file upload flaws, not only these three. Whether a PHP file in uploads actually runs depends on how the web server is set up. We covered that in detail in our Gravity Forms file upload analysis, which applies directly here. A server that refuses to run PHP from wp-content/uploads turns a web shell into an inert file.
Audit your forms as well. A File Upload field that nobody uses is attack surface with no benefit. Remove unused upload fields, and limit accepted file types to what the form needs.
Keep core in the same routine. These plugin flaws follow two WordPress core issues this summer, covered in our reports on the wp2shell core flaw and Click2Shell in WordPress 7.1.1. If a site does need cleanup, a clean backup is only useful when it predates the upload, which our piece on WordPress backup security explains.
Frequently Asked Questions
Which WordPress file upload flaws were attacked in September 2026?
Wordfence reported active exploitation of three: CVE-2026-32475 in Elementor Pro, CVE-2026-14894 in Super Forms and CVE-2026-27540 in Wholesale Lead Capture for WooCommerce. All three let an unauthenticated visitor upload a PHP file.
What versions fix them?
Elementor Pro 4.2.2, Super Forms 6.3.314 and Wholesale Lead Capture 2.0.3.2. Any later version also includes the fix.
Does an attacker need an account on the site?
No. All three file upload flaws work without logging in. The attacker only needs a public form that exposes the vulnerable upload handler.
How many attacks were reported?
Wordfence says its firewall blocked over 190,000 attempts against Elementor Pro, over 250,000 against Super Forms and over 100,000 against Wholesale Lead Capture. These are blocked attempts on Wordfence-protected sites, not confirmed compromises.
Is every Elementor Pro site vulnerable?
Only sites on 4.2.1 or earlier with a published form that includes a File Upload field, according to Patchstack and Wordfence. Elementor reportedly said the multiple file upload option must also be enabled. Update every site either way.
Was All-in-One WP Migration exploited too?
Not as far as named security firms had confirmed by September 27, 2026. Its September flaw is a SQL injection triggered during a backup restore, fixed in 7.110. Newer issues are fixed in 7.111.
If I update, am I safe?
You are safe from new uploads through these file upload flaws. You are not protected from a file an attacker placed before the update. Check the uploads folder for PHP files and review administrator accounts.
Where do the uploaded files end up?
For Elementor Pro, Patchstack and Wordfence both point to `wp-content/uploads/elementor/forms/`. For the other two, Wordfence advises checking the uploads directory generally for unexpected `.php` files.
How do I check many client sites at once?
Use WP-CLI’s `wp plugin list` with an alias group that covers your sites, or your managed host’s dashboard. Search for the slugs elementor-pro, super-forms and woocommerce-wholesale-lead-capture, and include inactive plugins.
Why was Wholesale Lead Capture attacked months after the patch?
Attackers target sites that never updated. The fix came out in February 2026, but Wordfence saw large waves of attempts in June, July and August. Premium plugins that update through a vendor license can fall behind when the license lapses.