Critical Everest Forms Pro flaw exploited to take over WordPress sites
ID: 2f1ccb72-840c-5e88-9fdd-22d7374cd8e7
STIX ID: report--2f1ccb72-840c-5e88-9fdd-22d7374cd8e7
Feed Name: Bleeping Computer
Everest Forms Pro (versions 1.9.12 and earlier) contains a critical unauthenticated RCE (CVE-2026-3300) in its Complex Calculation feature that uses eval() on constructed PHP code, allowing attackers to inject PHP (e.g., wp_insert_user()) to create administrator accounts and fully compromise WordPress sites; a patch was issued on March 18, but active exploitation began April 13 with Wordfence blocking over 29,300 attempts and identifying specific offending IPs and the account string "diksimarina" as an IOC.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
