Everest Forms Pro RCE exploitation and patch response
Case score 91
Case score is a discovery signal based on public evidence, not a guaranteed risk rating. Use it to decide what to review first, then verify important details from the linked sources.
- Total
- 91
- Main story score
- 87
- Related evidence lift
- +4 / 20
- Contributing updates
- 1
- Context updates
- 1
- Vulnerability Primary anchor for the exploited Everest Forms Pro flaw CVE-2026-3300. main
- Exploitation Wave Confirms ongoing in-the-wild abuse and blocked-attempt volume for the same CVE. contributes
- Security Patch Release Provides the remediation timeline and fix version for the same exploited flaw. context
Overview
Latest development Open development history Wordfence publishes indicators for CVE-2026-3300 exploitation in Everest Forms Pro Wordfence publishes attacker indicators for CVE-2026-3300, saying exploitation attempts originate primarily from 202.56.2[.]126 and 209.146.60.26 and advising defenders to block them and review administrator accounts and logs for suspicious activity, especially entries containing 'diksimarina'.
-
Wordfence blocks 17,900 Everest Forms Pro exploit attempts in a May 16 surge
Wordfence said its firewall blocked more than 29,300 exploit attempts against Everest Forms Pro, and a surge on May 16, 2026 accounted for over 17,900 blocked attempts in a single day.
-
Everest Forms Pro attackers begin exploiting CVE-2026-3300
Wordfence telemetry shows unauthenticated attackers began exploiting CVE-2026-3300 against Everest Forms Pro WordPress sites on April 13, 2026, using the plugin's Complex Calculation feature to reach PHP eval() and potentially create rogue administrator accounts or plant webshells.
-
Everest Forms Pro 1.9.13 patches CVE-2026-3300
Version 1.9.13 of Everest Forms Pro was released to fix CVE-2026-3300, a CVSS 9.8 remote code execution flaw affecting all versions up to and including 1.9.12.
-
Wordfence discloses active exploitation of Everest Forms Pro CVE-2026-3300
Wordfence disclosed that Everest Forms Pro for WordPress has a critical remote code execution flaw tracked as CVE-2026-3300, rated 9.8 on the CVSS scale and affecting releases through 1.9.12; WPEverest fixed the bug in 1.9.13, and administrators were urged to update affected sites without delay.