Attackers are exploiting Super Forms and Elementor Pro flaws to upload PHP files and execute code on WordPress sites.

Second-order SQL injection flaw (CVE-2026-19949) in the All-in-One WP Migration and Backup plugin can be exploited for complete site compromise.

A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute…