Critical Everest Forms Pro flaw exploited to take over WordPress sites
A critical vulnerability (CVE-2026-3300) in the Everest Forms Pro WordPress plugin is being actively exploited by attackers to gain complete control over affected websites. This flaw allows for arbitrary code execution, enabling attackers to create administrator accounts and perform malicious actions on compromised systems. The vulnerability was reported and patched, but ongoing exploitation highlights the importance of timely updates and security monitoring.
Hackers are leveraging a significant security flaw in the Everest Forms Pro plugin for WordPress. The vulnerability, CVE-2026-3300, resides within the plugin’s Complex Calculation feature, allowing attackers to inject and execute malicious PHP code on the server. This is achieved by manipulating form input values to bypass sanitization measures and utilize the ‘eval ()’ function, resulting in unauthorized code execution. The exploitation is being actively observed by security vendors like Wordfence, which has documented over 29,300 attempts to exploit the vulnerability.