CVE-2026-3300
CVSS 9.8 CRITICAL: the Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. EPSS 39% (98th percentile).
Vulnerabilities & Exploits · Web App Attack
A form plugin bug turned user input into PHP execution, so an unauthenticated request could become full WordPress takeover. The standard fix is not just patching the plugin, because a successful hit can leave behind rogue admin accounts and webshells that keep the site compromised after the code is updated.
The flaw is in Everest Forms Pro’s Complex Calculation feature. It affects version 1.9.12 and earlier, is tracked as CVE-2026-3300, and was patched in 1.9.13. Wordfence says it has already blocked more than 29,300 exploit attempts, with attackers using the bug to register a fake administrator account and push the campaign at scale across a product with about 4,000 active installs.
The risk now is not just exposure to a bad form submission. Any affected site needs to assume admin credentials or backdoor access may already exist, because patching closes the hole but does not remove what attackers created through it.
4 sources · Jun 8
CVSS 9.8 CRITICAL: the Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. EPSS 39% (98th percentile).
SecurityWeek
Everest Forms Vulnerability Exploited to Hack WordPress Sites
The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months.
originalBleepingComputer
Critical Everest Forms Pro flaw exploited to take over WordPress sites
Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website.
originalThe Hacker News
Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
Threat actors are actively exploiting CVE-2026-3300, a critical RCE vulnerability (CVSS 9.8) in Everest Forms Pro WordPress plugin (4,000+ installs).
originalPart of the PlainSec briefing for 2026-06-07
Every edition of this story: WordPress Form Bug Hands Out Admin Access