Back to Feed
VulnerabilitiesJun 8, 2026

Everest Forms Vulnerability Exploited to Hack WordPress Sites

Everest Forms Pro plugin vulnerability exploited to hack WordPress sites.

Summary

A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin, affecting over 100,000 sites, has been actively exploited for two months. Attackers can inject and execute arbitrary PHP code, enabling them to create admin accounts or deploy web shells for full site takeover. The flaw was patched in version 1.9.13.

Full text

A critical-severity vulnerability in the Everest Forms Pro WordPress plugin has been exploited in the wild for months for site takeover, Defiant warns. Present on more than 100,000 WordPress websites, Everest Forms is designed for creating contact forms, order forms, payment forms, and surveys. Tracked as CVE-2026-3300 (CVSS score of 9.8), the security defect allows unauthenticated, remote attackers to inject PHP code into form fields using the Complex Calculation feature. Although user input is sanitized, a vulnerable function in the plugin does not escape single quotes and other characters, and adds the provided values to a PHP code string. A remote, unauthenticated attacker can supply a value containing a single quote followed by malicious PHP code and a comment character, which results in the injection of PHP code that is executed on the server. “This makes it possible for unauthenticated attackers to inject and execute arbitrary PHP code on the server by submitting a crafted value in any string-type form field (text, email, URL, select, radio) when a form uses the ‘Complex Calculation’ feature,” Defiant explains.Advertisement. Scroll to continue reading. Threat actors can exploit the security flaw to create administrative accounts or deploy web shells, which allows them to take over vulnerable WordPress sites. The CVE was addressed in March, in Everest Forms Pro version 1.9.13, and in-the-wild exploitation started on April 13, Defiant says. To date, the WordPress security firm has blocked over 29,000 exploit attempts targeting the vulnerability. Most of the observed attacks attempted to create a new administrative account named ‘diksimarina’. WordPress users are advised to update their Everest Forms Pro deployments to version 1.9.13 or newer as soon as possible, and to look for unauthorized administrator accounts, mainly for the username ‘diksimarina’ or the email address ‘[email protected]’. Related: Kirki, Burst Statistics WordPress Plugin Flaws in Attackers’ Crosshairs Related: WP Maps Pro Vulnerability Exploited to Take Over WordPress Sites Related: CISA Urges Immediate Patching of Exploited LiteSpeed cPanel Plugin Zero-Day Related: Ally WordPress Plugin Flaw Exposes Over 200,000 Websites to Attacks Written By Ionut Arghire Ionut Arghire is an international correspondent for SecurityWeek. Daily Briefing Newsletter Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights. More from Ionut Arghire Emphere Raises $2.1 Million for AI-Powered Vulnerability RemediationOpal Security Raises $23 Million for AI-Native Identity GovernanceHackers Leak DentaQuest Information Impacting 2.6 MillionChrome 149 Patches 429 VulnerabilitiesFive Eyes: Chinese Spies Target Government, Military Staff With Fake Job OpportunitiesMirasvit Vulnerability Exploited to Execute Code on Magento ServersChinese Cybercrime Group in Spotlight for Record Campaign PaceOver 1.4 Million Accounts Disrupted in Cybercrime Crackdown Latest News WhatsApp Catches Spyware Firm NSO Defying No-Hacking Court OrderCybersecurity M&A Roundup: 26 Deals Announced in May 2026174,000 Impacted by Lansing Community College Data BreachSilent Ransom Group Uses DNS Fast Flux in AttacksOpenAI Rolling Out ChatGPT Account Security ControlsAnthropic Urges Industry Coordination to Allow for a ‘Pause’ in AI Development if Risks GrowSolarWinds Serv-U Vulnerability Exploited in the WildMeta Says 20,000 Instagram Accounts Hacked via AI Tool Abuse Trending Daily Briefing NewsletterSubscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts. Webinar: Third-Party Risk in Practice June 4, 2026 Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice. Register Virtual Roundtable: CISO Forum 2026 Mid-Year Review June 10, 2026 Explore how attackers are using AI to scale threats and how security teams can respond with AI-driven defenses. Protecting against unmonitored use of generative AI (Shadow AI) in business units and building and enforcing AI governance frameworks. Register People on the MoveOpal Security has appointed CPO, CTO, VP of Field Engineering, VP of Marketing, and Head of Product and Solutions Marketing.The Department of the Air Force has appointed Ashley Devoto as Chief Information Officer.Bartley Richardson has been named Chief AI and Autonomous Systems Officer at CrowdStrike.More People On The MoveExpert Insights The Zero-Knowledge Threat Actor and the End of Responsible Disclosure AI can help attackers generate malware, create malicious payloads, bypass simple security checks, and convert vague malicious intent into functional code. (Etay Maor) Raising the Cybersecurity Stakes: Ante up for the Agentic Era CISOs are now facing machine-speed attacks and asking, “How do I agent?” The industry must provide remediation at scale. (Nadir Izrael) Caught Off Guard: Securing AI After It Hits Production As enterprises rush AI projects into production, security teams are increasingly being forced into reactive mode. (Joshua Goldfarb) Cyber Resilience is the New Business Continuity Plan The organizations best prepared to face disruption are those that align security, continuity and risk management around what the business cannot afford to lose. (Steve Durbin) Enhancing Data Center Security Without Sacrificing Performance For AI data centers, where the stakes are the highest and performance constraints are the tightest, security and performance are no longer a zero-sum game. (Nadir Izrael) Flipboard Reddit Whatsapp Whatsapp Email

Indicators of Compromise

  • cve — CVE-2026-3300
  • malware — web shells

Entities

Everest Forms Pro (product)WordPress (technology)Defiant (vendor)