logo

Hackers Actively Exploiting WordPress Plugin Vulnerability to Inject Malicious PHP Code

ID: 585ba014-f50e-518c-97ec-d7dd4cf84ba0

STIX ID: report--585ba014-f50e-518c-97ec-d7dd4cf84ba0

Feed Name: cybersecurityNews.com

Threat Score
88/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Abinaya

...
...

**Executive Summary:** A critical unauthenticated RCE in Everest Forms Pro (CVE-2026-3300, CVSS 9.8) is being actively exploited in the wild to inject PHP via the plugin's Complex Calculation feature—threat actors create rogue admin accounts and deploy webshells; operators should immediately upgrade to 1.9.13, audit accounts, and block known malicious IPs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.