Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave Security Patch Release

Everest Forms Pro RCE exploitation and patch response

Updated 06.06.2026 17:09
Case score 91
Members 3 First seen 04.06.2026 19:15 Latest activity 06.06.2026 17:09

Overview

Active exploitation of **CVE-2026-3300** in **Everest Forms Pro** has turned a critical **WordPress** plugin flaw into an ongoing site-compromise risk. The bug affects versions through **1.9.12**, allows unauthenticated PHP execution through the **Complex Calculation** feature, and has been used since **April 13, 2026** to pursue administrator-account creation and broader takeover. More than **29,300 exploit attempts** have been blocked, while the vendor fix has been available since **March 18, 2026** in **1.9.13**. Organizations running the plugin need to treat unpatched sites as exposed and check whether compromise occurred before the update was applied.
Latest development Open development history 4 earlier developments Wordfence publishes indicators for CVE-2026-3300 exploitation in Everest Forms Pro Wordfence publishes attacker indicators for CVE-2026-3300, saying exploitation attempts originate primarily from 202.56.2[.]126 and 209.146.60.26 and advising defenders to block them and review administrator accounts and logs for suspicious activity, especially entries containing 'diksimarina'.
  1. Earlier development

    Wordfence blocks 17,900 Everest Forms Pro exploit attempts in a May 16 surge

    Wordfence said its firewall blocked more than 29,300 exploit attempts against Everest Forms Pro, and a surge on May 16, 2026 accounted for over 17,900 blocked attempts in a single day.

  2. Earlier development

    Everest Forms Pro attackers begin exploiting CVE-2026-3300

    Wordfence telemetry shows unauthenticated attackers began exploiting CVE-2026-3300 against Everest Forms Pro WordPress sites on April 13, 2026, using the plugin's Complex Calculation feature to reach PHP eval() and potentially create rogue administrator accounts or plant webshells.

  3. Earlier development

    Everest Forms Pro 1.9.13 patches CVE-2026-3300

    Version 1.9.13 of Everest Forms Pro was released to fix CVE-2026-3300, a CVSS 9.8 remote code execution flaw affecting all versions up to and including 1.9.12.

  4. Earlier development

    Wordfence discloses active exploitation of Everest Forms Pro CVE-2026-3300

    Wordfence disclosed that Everest Forms Pro for WordPress has a critical remote code execution flaw tracked as CVE-2026-3300, rated 9.8 on the CVSS scale and affecting releases through 1.9.12; WPEverest fixed the bug in 1.9.13, and administrators were urged to update affected sites without delay.

Signals

Impact signals
Exploitation
CVEs/products
Remediation

Tooling context

2 tools
Tools

Technical intelligence

Existing Case data

Member happenings

Vulnerability Everest Forms Pro plugin actively exploited RCE (CVE-2026-3300)
Updated 04.06.2026 19:15 Lead Contribution 87
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**Everest Forms Pro** has an **actively exploited** critical **remote code execution** flaw, **CVE-2026-3300**, that lets unauthenticated attackers run **PHP** and take over **WordPress** sites. The bug affects versions through **1.9.12**, and **WPEverest** fixed it in **1.9.13** on **March 18, 2026**. Wordfence says abuse began on **April 13, 2026**, and its firewall has blocked more than **29,300 exploit attempts** so far.

Exploitation Wave Everest Forms Pro CVE-2026-3300 active exploitation wave
Updated 05.06.2026 11:38 Scoring Support Contribution 1
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

Active exploitation of **CVE-2026-3300** in **Everest Forms Pro** is driving **complete site compromise** risk for WordPress sites. Attackers have been using the flaw for arbitrary code execution since **April 13, 2026**. More than **29,300 exploit attempts** have already been blocked, showing sustained exploitation at scale.

Security Patch Release Everest Forms Pro plugin patch for CVE-2026-3300
Updated 06.06.2026 17:09 Context
Exploitation Active Exploitation Patch Patch Available

The **Everest Forms developer** released a patch for **CVE-2026-3300** in **Everest Forms Pro** on **March 18**, closing an **unauthenticated arbitrary code execution** flaw affecting **versions 1.9.12 and earlier**. The update matters because the vulnerable plugin could let attackers gain **complete control** of WordPress sites before administrators apply the fix.