Find notable cyber news and cases, enriched with sources, timelines, and signals.
Vulnerability Exploitation Wave Security Patch Release

Everest Forms Pro RCE exploitation and patch response

Updated 06.06.2026 17:09
Case score 91
Case score 91 Members 3 Latest activity 06.06.2026 17:09
Active exploitation Patch available CVSS: 9.8 Critical
Members 3 First seen 04.06.2026 19:15 Last seen 06.06.2026 17:09 Updated 06.06.2026 17:09

Overview

Active exploitation of **CVE-2026-3300** in **Everest Forms Pro** has turned a critical **WordPress** plugin flaw into an ongoing site-compromise risk. The bug affects versions through **1.9.12**, allows unauthenticated PHP execution through the **Complex Calculation** feature, and has been used since **April 13, 2026** to pursue administrator-account creation and broader takeover. More than **29,300 exploit attempts** have been blocked, while the vendor fix has been available since **March 18, 2026** in **1.9.13**. Organizations running the plugin need to treat unpatched sites as exposed and check whether compromise occurred before the update was applied.

Signals

4 derived
Impact signals
Affected WordPress websites using Everest Forms Pro
Exploitation
Exploitation Active exploitation CVSS 9.8 Critical
CVEs/products
CVE
Remediation
Remediation Patch available

Malware context

0 families · 2 tools
Tools
Google Tag Manager Stripe

Member happenings

3 related
Vulnerability Everest Forms Pro plugin actively exploited RCE (CVE-2026-3300)
Updated 04.06.2026 19:15 Lead Contribution 87
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

**Everest Forms Pro** has an **actively exploited** critical **remote code execution** flaw, **CVE-2026-3300**, that lets unauthenticated attackers run **PHP** and take over **WordPress** sites. The bug affects versions through **1.9.12**, and **WPEverest** fixed it in **1.9.13** on **March 18, 2026**. Wordfence says abuse began on **April 13, 2026**, and its firewall has blocked more than **29,300 exploit attempts** so far.

Exploitation Wave Everest Forms Pro CVE-2026-3300 active exploitation wave
Updated 05.06.2026 11:38 Scoring Support Contribution 1
Exploitation Active Exploitation CVSS 9.8 Critical Patch Patch Available

Active exploitation of **CVE-2026-3300** in **Everest Forms Pro** is driving **complete site compromise** risk for WordPress sites. Attackers have been using the flaw for arbitrary code execution since **April 13, 2026**. More than **29,300 exploit attempts** have already been blocked, showing sustained exploitation at scale.

Security Patch Release Everest Forms Pro plugin patch for CVE-2026-3300
Updated 06.06.2026 17:09 Context
Exploitation Active Exploitation Patch Patch Available

The **Everest Forms developer** released a patch for **CVE-2026-3300** in **Everest Forms Pro** on **March 18**, closing an **unauthenticated arbitrary code execution** flaw affecting **versions 1.9.12 and earlier**. The update matters because the vulnerable plugin could let attackers gain **complete control** of WordPress sites before administrators apply the fix.