CVE-2026-3300
CVSS 9.8 CRITICAL: the Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. EPSS 4% (91º percentile).
Vulnerabilità ed exploit · Attacco ad app web
Un bug di un plugin per form ha trasformato l’input dell’utente in esecuzione di PHP, quindi una richiesta non autenticata poteva diventare un takeover completo di WordPress. La correzione standard non è solo patchare il plugin, perché un colpo riuscito può lasciare dietro di sé account amministratore non autorizzati e webshell che mantengono il sito compromesso dopo l’aggiornamento del codice.
4 fonti · 8 giu
CVSS 9.8 CRITICAL: the Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. EPSS 4% (91º percentile).
SecurityWeek
Everest Forms Vulnerability Exploited to Hack WordPress Sites
The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months.
originaleBleepingComputer
Critical Everest Forms Pro flaw exploited to take over WordPress sites
Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website.
originaleThe Hacker News
Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
Threat actors are actively exploiting CVE-2026-3300, a critical RCE vulnerability (CVSS 9.8) in Everest Forms Pro WordPress plugin (4,000+ installs).
originalePart of the PlainSec briefing for 2026-06-07
Every edition of this story: Bug di WordPress Form Assegna Accesso Admin