Vulnerability
Exploitation Wave
Security Patch Release
Everest Forms Pro RCE exploitation and patch response
Updated 06.06.2026 17:09
Case score 91
Score breakdown
- Total
- 91
- Lead score
- 87
- Support bonus
- +4 / 20
- Scoring support
- 1
- Context members
- 1
Top contributors
- Vulnerability Primary anchor for the exploited **Everest Forms Pro** flaw **CVE-2026-3300**. base
- Exploitation Wave Confirms ongoing in-the-wild abuse and blocked-attempt volume for the same CVE. support
- Security Patch Release Provides the remediation timeline and fix version for the same exploited flaw. context
Case score 91
Members 3
Latest activity 06.06.2026 17:09
Active exploitation
Patch available
CVSS: 9.8 Critical
Members 3
First seen 04.06.2026 19:15
Last seen 06.06.2026 17:09
Updated 06.06.2026 17:09
Overview
Active exploitation of **CVE-2026-3300** in **Everest Forms Pro** has turned a critical **WordPress** plugin flaw into an ongoing site-compromise risk. The bug affects versions through **1.9.12**, allows unauthenticated PHP execution through the **Complex Calculation** feature, and has been used since **April 13, 2026** to pursue administrator-account creation and broader takeover.
More than **29,300 exploit attempts** have been blocked, while the vendor fix has been available since **March 18, 2026** in **1.9.13**. Organizations running the plugin need to treat unpatched sites as exposed and check whether compromise occurred before the update was applied.
Attackers are actively exploiting **CVE-2026-3300** in **Everest Forms Pro** to achieve unauthenticated remote code execution on vulnerable **WordPress** sites. The flaw affects versions through **1.9.12**, carries a **9.8 CVSS** rating, and can lead to full site takeover. Available evidence says exploitation began on **April 13, 2026**, after **WPEverest** had already released **1.9.13** on **March 18, 2026**.
The vulnerable path sits in the plugin's **Complex Calculation** feature, where user-controlled form input is concatenated into a PHP string that reaches eval(). Because the input handling does not escape single quotes and related PHP code context characters, a crafted value in a string-type field can inject arbitrary PHP. Observed payloads have attempted to create a rogue administrator account named **diksimarina**, and successful exploitation can also support web shells and persistent footholds.
Telemetry has recorded more than **29,300 blocked exploit attempts**, showing sustained abuse rather than isolated scanning. Defenders need to upgrade to **1.9.13** or later, review administrator accounts and logs for suspicious changes, and investigate whether exposed sites were compromised before patching. Available evidence does not identify the threat actor or confirm how many sites were actually compromised.
Signals
4 derivedImpact signals
Affected
WordPress websites using Everest Forms Pro
Exploitation
Exploitation
Active exploitation
CVSS
9.8 Critical
CVEs/products
CVE
Remediation
Remediation
Patch available
Malware context
0 families · 2 toolsTools
Google Tag Manager
Stripe
Member happenings
3 related
Vulnerability
Everest Forms Pro plugin actively exploited RCE (CVE-2026-3300)
Exploitation
Active Exploitation
CVSS
9.8 Critical
Patch
Patch Available
Vulnerability
Everest Forms Pro plugin actively exploited RCE (CVE-2026-3300)
Exploitation
Active Exploitation
CVSS
9.8 Critical
Patch
Patch Available
Exploitation Wave
Everest Forms Pro CVE-2026-3300 active exploitation wave
Exploitation
Active Exploitation
CVSS
9.8 Critical
Patch
Patch Available
Exploitation Wave
Everest Forms Pro CVE-2026-3300 active exploitation wave
Exploitation
Active Exploitation
CVSS
9.8 Critical
Patch
Patch Available
Security Patch Release
Everest Forms Pro plugin patch for CVE-2026-3300
Exploitation
Active Exploitation
Patch
Patch Available
Security Patch Release
Everest Forms Pro plugin patch for CVE-2026-3300
Exploitation
Active Exploitation
Patch
Patch Available