The Desk · The Wire · Hacked Today? · Data Center RSS
The Perimeter Site

Who Is Still Running Elementor Pro?

The Perimeter Desk
2026-09-04
# Who Is Still Running Elementor Pro? 440,000. That is the number of exploit attempts targeting remote code execution (RCE) vulnerabilities in the Super Forms and Elementor Pro WordPress plugins. To most people, it's just a large figure. To anyone who actually reads the wire, it's a scoreboard. It means that for every single person currently reading this, there are roughly 800 automated attempts to turn a WordPress site into a botnet node or a phishing redirect. When a vendor calls a flaw "critical," they're usually just trying to avoid a lawsuit from their enterprise clients. I believe the word has to be earned. These RCEs earned it. They aren't targeted strikes by sophisticated actors; this is a spray-and-pray campaign on an industrial scale. The volume here is unusual because it targets the periphery of the stack—plugins—rather than the core. It touches the millions of small business owners and freelance developers who treat their plugin directory as a "set and forget" checklist. They aren't monitoring changelogs; they're monitoring their conversion rates. Some will argue that Web Application Firewalls (WAFs) mitigate this risk by filtering out the noise. This is a fundamental misunderstanding of how these attacks work. A WAF is a filter, not a fix. It doesn't remove the vulnerability; it just hides the evidence until a researcher or an attacker finds a bypass that renders the filter useless. You aren't secure; you're just lucky for the moment. The second-order effect here hits the shared hosting providers. When 440,000 attempts hammer a set of IP ranges, those IPs get flagged by global threat feeds as malicious. Suddenly, an innocent blog on the same server as a compromised Elementor site finds its outbound emails hitting spam folders or its traffic blocked by corporate firewalls. The neighbor's broken window just locked your front door. This week has been loud. We've seen 118 vulnerability stories and 92 reports of exploits in the wild. For those who prefer the official channels, CISA just added CVE-2026-9586—a SQL injection in Sangoma Switchvox—to its catalog on September 2. The federal patch deadline is September 5. That's a three-day window to secure your voice-over-IP infrastructure before the government considers you non-compliant. Most teams can't even get a change request approved in three days, let alone execute it. The reality is that we've stopped patching for security and started patching for compliance. If you're waiting for a CISA directive to update your plugins or your PBX, you've already lost the argument. You aren't managing risk; you're just documenting the failure. I wonder how many of those 440,000 attempts actually landed. I suspect the number is high enough that we'll see a spike in "unexplained" server load across mid-tier hosting providers by next Tuesday.
◼

Sources

The reporting this analysis was built from. Follow the originals before acting on anything here.

  1. Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day The Hacker News
  2. Sangoma Switchvox Vulnerabilities Exploited in the Wild SecurityWeek
  3. (LEAD) Nearly 40 mln Tving accounts compromised in massive data breach: probe - Yonhap News Agency Google News Security
  4. Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild - CyberSecurityNews Google News Security
  5. Google warns of new Chrome zero-day flaw exploited in attacks BleepingComputer
  6. Data breach at South Korean streaming service Tving affects 39 million accounts - MLex Google News Security
  7. Tving Data Breach Exposes 39.54 Million Accounts, Double Initial Estimate - thelec.net Google News Security
  8. Critical Citrix NetScaler auth bypass now leveraged in attacks BleepingComputer

How stories are selected and rated

← More from the Desk Live Wire →

About · Methodology · Contact · Privacy

Tracking a CVE from this story? Hazard shows which vulnerabilities are confirmed exploited in the wild — and what the resulting breaches have cost UK organisations.

DISCLAIMER: Articles on this site are generated automatically from public security news feeds for educational and informational purposes. They may contain errors, and nothing here constitutes security, legal, or compliance advice. Verify details against original advisories and vendor bulletins before acting on them.