logo

Everest Forms Pro Flaw Exploited in the Wild to Hijack WordPress Sites

ID: ab77ce27-f085-5c46-acc9-070586f76be5

STIX ID: report--ab77ce27-f085-5c46-acc9-070586f76be5

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-06-04

Date Updated: 2026-06-04

Author: Ddos

...
...

A critical RCE vulnerability in the Everest Forms Pro WordPress plugin (CVE-2026-3300, CVSS 9.8) allows unauthenticated attackers to inject PHP via improperly sanitized form calculations in `process_filter()` (which uses eval), and threat telemetry shows large-scale automated exploitation beginning April 13, 2026 — including attempts to create a rogue admin account `diksimarina`. Administrators should immediately update to Everest Forms Pro v1.9.13 or later and audit user accounts for unauthorized handles.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.