Find notable cyber news and cases, enriched with sources, timelines, and signals.

Everest Forms Pro plugin patch for CVE-2026-3300

Security Patch Release
First reported
Last updated
Happening score
H score 43
1 unique sources, 1 articles

Summary

Hide ▲

The Everest Forms developer released a patch for CVE-2026-3300 in Everest Forms Pro on March 18, closing an unauthenticated arbitrary code execution flaw affecting versions 1.9.12 and earlier. The update matters because the vulnerable plugin could let attackers gain complete control of WordPress sites before administrators apply the fix.

Cases

Related Happenings

Gravity SMTP security patch release for CVE-2026-4020

Security Patch Release
H score16 First: 20.06.2026 12:56 Last: 20.06.2026 12:56 Sources 1

About this happening: Gravity SMTP released version 2.1.5 to fix CVE-2026-4020, closing a medium-severity information disclosure flaw in the WordPress plugin. The patch addresses a bug...

JCE Pro 2.9.99.6 patch for CVE-2026-48907

Security Patch Release
H score46 First: 17.06.2026 13:09 Last: 17.06.2026 13:09 Sources 1

About this happening: JCE security team released JCE Pro 2.9.99.6 in early June 2026 to fix CVE-2026-48907 in the Widget Factory Joomla Content Editor (JCE) plugin. The update addre...

Everest Forms Pro CVE-2026-3300 active exploitation wave

Exploitation Wave
H score87 First: 05.06.2026 11:38 Last: 05.06.2026 11:38 Sources 1

How related: According to Wordfence data, active exploitation started on April 13, with the firewall blocking over 29,300 attempts.

About this happening: Active exploitation of CVE-2026-3300 in Everest Forms Pro is driving complete site compromise risk for WordPress sites. Attackers have been using the flaw for arbitrar...

The vendor security patch release for CVE-2026-8206

Security Patch Release
H score89 First: 03.06.2026 01:12 Last: 03.06.2026 01:12 Sources 1

About this happening: Kirki - Freeform Page Builder, Website Builder & Customizer shipped version 6.0.7 to fix CVE-2026-8206, a privilege-escalation flaw that could let attackers take over...

WP Maps Pro 6.1.1 security patch for CVE-2026-8732

Security Patch Release
H score49 First: 31.05.2026 17:06 Last: 31.05.2026 17:06 Sources 1

About this happening: WP Maps Pro 6.1.1 was released to fix CVE-2026-8732, giving WordPress administrators a patch for a flaw that enabled unauthenticated administrator-account creation. Th...

Timeline

  1. 06.06.2026 17:09 2 articles · 1mo ago

    Everest Forms developer patches CVE-2026-3300 in Everest Forms Pro

    Mitigation Patch Update

    The Everest Forms developer releases a patch for CVE-2026-3300 in Everest Forms Pro on March 18, closing an unauthenticated arbitrary code execution flaw in versions 1.9.12 and earlier that can be triggered through the plugin’s Complex Calculation feature.

    Show sources
  2. 06.06.2026 17:09 1 articles · 1mo ago

    Attackers exploit CVE-2026-3300 to create rogue WordPress administrator accounts

    Exploitation Observed

    On April 13, Wordfence telemetry shows active exploitation of CVE-2026-3300 against WordPress sites using Everest Forms Pro, with more than 29,300 blocked attempts and injected PHP code creating rogue administrator accounts such as 'diksimarina'.

    Show sources
  3. 06.06.2026 17:09 1 articles · 1mo ago

    Wordfence publishes indicators for CVE-2026-3300 exploitation in Everest Forms Pro

    Detection Ioc Update

    Wordfence publishes attacker indicators for CVE-2026-3300, saying exploitation attempts originate primarily from 202.56.2[.]126 and 209.146.60.26 and advising defenders to block them and review administrator accounts and logs for suspicious activity, especially entries containing 'diksimarina'.

    Show sources