Everest Forms Pro plugin actively exploited RCE (CVE-2026-3300)
Vulnerability
Updated: 04.06.2026 19:15
· First: 04.06.2026 19:15
· 📰 3 src / 3 articles
· H score: 53
Everest Forms Pro has an actively exploited critical remote code execution flaw, CVE-2026-3300, that lets unauthenticated attackers run PHP and take over WordPress sites. The bug affects versions through 1.9.12, and WPEverest fixed it in 1.9.13 on March 18, 2026. Wordfence says abuse began on April 13, 2026, and its firewall has blocked more than 29,300 exploit attempts so far.