logo

Critical Everest Forms Pro Flaw Exploited to Take Over WordPress Sites

ID: 169f6b75-1ff0-5234-ae91-b11e36add306

STIX ID: report--169f6b75-1ff0-5234-ae91-b11e36add306

Feed Name: CosmicBytez Labs

Threat Score
90/100

Date Published: 2026-06-06

Date Updated: 2026-06-11

...
...

**CVE-2026-3300 – Everest Forms Pro (critical, active exploitation):** A critical unauthenticated vulnerability in the Everest Forms Pro WordPress plugin enables remote full administrative takeover of sites; attackers are actively exploiting the flaw to install webshells, create rogue admins, exfiltrate form data, and redirect visitors. Site owners are advised to update or deactivate the plugin immediately, scan for compromises (unknown admin accounts, modified files, anomalous POSTs), and apply WAF mitigations while investigating.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.