Everest Forms Vulnerability Exploited to Hack WordPress Sites
The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. The post Everest Forms Vulnerability Exploited to Hack WordPress Sites appeared first on SecurityWeek .
AI Analysis
Technical Summary
The Everest Forms Pro WordPress plugin contains a critical remote code execution vulnerability tracked as CVE-2026-3300 with a CVSS score of 9.8. The vulnerability arises because the plugin's Complex Calculation feature improperly escapes single quotes and other characters when incorporating user input into PHP code strings. An unauthenticated attacker can submit crafted input containing a single quote followed by malicious PHP code and a comment character, resulting in arbitrary PHP code execution on the server. This allows attackers to create administrative accounts or deploy web shells, effectively taking over vulnerable WordPress sites. The vulnerability affects over 100,000 sites and has been exploited in the wild since April 2026. The issue was fixed in Everest Forms Pro version 1.9.13 released in March 2026.
Potential Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary PHP code on affected WordPress sites, leading to full site takeover. Attackers have used this to create unauthorized administrative accounts and deploy web shells. Over 29,000 exploit attempts have been blocked by security firms. The vulnerability impacts site integrity, confidentiality, and availability by enabling attacker control over the WordPress environment.
Mitigation Recommendations
An official patch addressing this vulnerability is available in Everest Forms Pro version 1.9.13 and later. Site administrators should update to this version immediately. Additionally, administrators should audit their WordPress sites for unauthorized administrator accounts, especially those with the username 'diksimarina' or the email address 'diksimarina@gmail.com'. No other specific mitigations are indicated by the vendor advisory.
Everest Forms Vulnerability Exploited to Hack WordPress Sites
Description
The flaw allows attackers to execute arbitrary code remotely and has been exploited in the wild for two months. The post Everest Forms Vulnerability Exploited to Hack WordPress Sites appeared first on SecurityWeek .
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The Everest Forms Pro WordPress plugin contains a critical remote code execution vulnerability tracked as CVE-2026-3300 with a CVSS score of 9.8. The vulnerability arises because the plugin's Complex Calculation feature improperly escapes single quotes and other characters when incorporating user input into PHP code strings. An unauthenticated attacker can submit crafted input containing a single quote followed by malicious PHP code and a comment character, resulting in arbitrary PHP code execution on the server. This allows attackers to create administrative accounts or deploy web shells, effectively taking over vulnerable WordPress sites. The vulnerability affects over 100,000 sites and has been exploited in the wild since April 2026. The issue was fixed in Everest Forms Pro version 1.9.13 released in March 2026.
Potential Impact
Successful exploitation allows unauthenticated remote attackers to execute arbitrary PHP code on affected WordPress sites, leading to full site takeover. Attackers have used this to create unauthorized administrative accounts and deploy web shells. Over 29,000 exploit attempts have been blocked by security firms. The vulnerability impacts site integrity, confidentiality, and availability by enabling attacker control over the WordPress environment.
Mitigation Recommendations
An official patch addressing this vulnerability is available in Everest Forms Pro version 1.9.13 and later. Site administrators should update to this version immediately. Additionally, administrators should audit their WordPress sites for unauthorized administrator accounts, especially those with the username 'diksimarina' or the email address 'diksimarina@gmail.com'. No other specific mitigations are indicated by the vendor advisory.
Technical Details
- Article Source
- {"url":"https://www.securityweek.com/everest-forms-vulnerability-exploited-to-hack-wordpress-sites/","fetched":true,"fetchedAt":"2026-06-08T12:18:38.827Z","wordCount":1017}
Threat ID: 6a26b31ee29bf47b50e253e9
Added to database: 6/8/2026, 12:18:38 PM
Last enriched: 6/8/2026, 12:18:45 PM
Last updated: 6/9/2026, 6:24:29 AM
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.