logo

Everest Forms Pro WordPress Flaw is Handing Attackers Admin Access

ID: bc3e17d6-cfd1-52fe-a6c4-4a99f32d2a26

STIX ID: report--bc3e17d6-cfd1-52fe-a6c4-4a99f32d2a26

Feed Name: Security Affairs

Threat Score
75/100

Date Published: 2026-06-08

Date Updated: 2026-06-08

Author: Pierluigi Paganini

...
...

Everest Forms Pro contains a PHP injection vulnerability (CVE-2026-3300) in its Complex Calculation feature that attackers have been actively exploiting to create backdoor administrator accounts (notably username 'diksimarina'); Wordfence blocked ~29,300 attempts, observed mass activity on 2026-05-16, and provides IP indicators and remediation steps — update to v1.9.13 immediately, search for the malicious admin account and web shells, rotate credentials, and audit files and logs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.