Everest Forms Pro CVE-2026-3300 active exploitation wave
Exploitation Wave
Summary
Hide ▲
Show ▼
Active exploitation of CVE-2026-3300 in Everest Forms Pro is driving complete site compromise risk for WordPress sites. Attackers have been using the flaw for arbitrary code execution since April 13, 2026. More than 29,300 exploit attempts have already been blocked, showing sustained exploitation at scale.
Cases
Related Happenings
Everest Forms Pro plugin patch for CVE-2026-3300
Security Patch Release
H score43
First: 06.06.2026 17:09
Last: 06.06.2026 17:09
Sources 1
How related:
Researcher h0xilo submitted the CVE-2026-3300 vulnerability through Wordfence in February, and on March 18, the Everest Forms developer released a patch that addresses the issue.
About this happening:
The Everest Forms developer released a patch for CVE-2026-3300 in Everest Forms Pro on March 18, closing an unauthenticated arbitrary code execution flaw affec...
Everest Forms Pro plugin patch for CVE-2026-3300
Security Patch ReleaseHow related: Researcher h0xilo submitted the CVE-2026-3300 vulnerability through Wordfence in February, and on March 18, the Everest Forms developer released a patch that addresses the issue.
About this happening: The Everest Forms developer released a patch for CVE-2026-3300 in Everest Forms Pro on March 18, closing an unauthenticated arbitrary code execution flaw affec...
FFmpeg parser/demuxer overflows (multiple vulnerabilities)
Vulnerability
H score36
First: 06.06.2026 10:28
Last: 06.06.2026 10:28
Sources 1
About this happening:
FFmpeg now has 21 confirmed zero-days, creating risk for any product that bundles the media library and processes untrusted video input. The findings include heap and st...
FFmpeg parser/demuxer overflows (multiple vulnerabilities)
VulnerabilityAbout this happening: FFmpeg now has 21 confirmed zero-days, creating risk for any product that bundles the media library and processes untrusted video input. The findings include heap and st...
Everest Forms Pro plugin actively exploited RCE (CVE-2026-3300)
Vulnerability
H score87
First: 04.06.2026 19:15
Last: 04.06.2026 19:15
Sources 1
How related:
The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution bug impacting all versions of the plugin up to, and including, 1.9.12.
About this happening:
Everest Forms Pro has an actively exploited critical remote code execution flaw, CVE-2026-3300, that lets unauthenticated attackers run PHP and take over Wor...
Everest Forms Pro plugin actively exploited RCE (CVE-2026-3300)
VulnerabilityHow related: The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution bug impacting all versions of the plugin up to, and including, 1.9.12.
About this happening: Everest Forms Pro has an actively exploited critical remote code execution flaw, CVE-2026-3300, that lets unauthenticated attackers run PHP and take over Wor...
Linux kernel XFRM ESP-in-TCP local privilege escalation (CVE-2026-46300)
Vulnerability
H score35
First: 14.05.2026 10:06
Last: 14.05.2026 10:06
Sources 1
About this happening:
Fragnesia adds a fresh Linux kernel local privilege-escalation path, putting unprivileged local attackers on a route to root access across major distributions. The...
Linux kernel XFRM ESP-in-TCP local privilege escalation (CVE-2026-46300)
VulnerabilityAbout this happening: Fragnesia adds a fresh Linux kernel local privilege-escalation path, putting unprivileged local attackers on a route to root access across major distributions. The...
Latest development: 14.05.2026 16:00
Cloud security firm Wiz identified Fragnesia (CVE-2026-46300) in the Dirty Frag family, a Linux local privilege escalation that lets unprivileged local users gain root by corrupting the kernel page cache of read-only files. William Bowling of Zellic and the V12 team were credited with the discovery, and a working proof-of-concept exploit was published on May 13, 2026.
MetInfo CMS unauthenticated PHP code injection actively exploited remote code execution flaw (CVE-2026-29014)
Vulnerability
H score53
First: 05.05.2026 14:56
Last: 05.05.2026 14:56
Sources 1
About this happening:
CVE-2026-29014 in MetInfo CMS is actively exploited, putting versions 7.9, 8.0, and 8.1 at risk of remote code execution and full server takeover. MetInfo...
MetInfo CMS unauthenticated PHP code injection actively exploited remote code execution flaw (CVE-2026-29014)
VulnerabilityAbout this happening: CVE-2026-29014 in MetInfo CMS is actively exploited, putting versions 7.9, 8.0, and 8.1 at risk of remote code execution and full server takeover. MetInfo...
Timeline
-
05.06.2026 11:38 1 articles · 1mo ago
Everest Forms Pro 1.9.13 patches CVE-2026-3300
Mitigation Patch UpdateVersion 1.9.13 of Everest Forms Pro was released to fix CVE-2026-3300, a CVSS 9.8 remote code execution flaw affecting all versions up to and including 1.9.12.
Show sources
- Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites — thehackernews.com — 05.06.2026 11:38
-
05.06.2026 11:38 1 articles · 1mo ago
Attackers begin exploiting CVE-2026-3300 in Everest Forms Pro
Exploitation ObservedAttackers were observed exploiting CVE-2026-3300 in Everest Forms Pro starting April 13, 2026, using crafted string-type form field input through the Complex Calculation feature to execute arbitrary PHP code and enable complete site compromise.
Show sources
- Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites — thehackernews.com — 05.06.2026 11:38
-
05.06.2026 11:38 3 articles · 1mo ago
Wordfence details active Everest Forms Pro CVE-2026-3300 exploitation
Initial DisclosureWordfence reported active exploitation of Everest Forms Pro CVE-2026-3300 on June 5, 2026, saying more than 29,300 exploit attempts had been blocked to date and that attackers commonly tried to create an administrator account named diksimarina with email address [email protected].
Show sources
- Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites — thehackernews.com — 05.06.2026 11:38
- Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites — thehackernews.com — 05.06.2026 11:38
- Critical Everest Forms Pro flaw exploited to take over WordPress sites — www.bleepingcomputer.com — 06.06.2026 17:09