Everest Forms Pro WordPress Flaw is Handing Attackers Admin Access
ID: bc3e17d6-cfd1-52fe-a6c4-4a99f32d2a26
STIX ID: report--bc3e17d6-cfd1-52fe-a6c4-4a99f32d2a26
Feed Name: Security Affairs
Everest Forms Pro contains a PHP injection vulnerability (CVE-2026-3300) in its Complex Calculation feature that attackers have been actively exploiting to create backdoor administrator accounts (notably username 'diksimarina'); Wordfence blocked ~29,300 attempts, observed mass activity on 2026-05-16, and provides IP indicators and remediation steps — update to v1.9.13 immediately, search for the malicious admin account and web shells, rotate credentials, and audit files and logs.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
