Everest Forms Pro plugin patch for CVE-2026-3300
Security Patch Release
Summary
Hide ▲
Show ▼
The Everest Forms developer released a patch for CVE-2026-3300 in Everest Forms Pro on March 18, closing an unauthenticated arbitrary code execution flaw affecting versions 1.9.12 and earlier. The update matters because the vulnerable plugin could let attackers gain complete control of WordPress sites before administrators apply the fix.
Cases
Related Happenings
Gravity SMTP security patch release for CVE-2026-4020
Security Patch Release
H score16
First: 20.06.2026 12:56
Last: 20.06.2026 12:56
Sources 1
About this happening:
Gravity SMTP released version 2.1.5 to fix CVE-2026-4020, closing a medium-severity information disclosure flaw in the WordPress plugin. The patch addresses a bug...
Gravity SMTP security patch release for CVE-2026-4020
Security Patch ReleaseAbout this happening: Gravity SMTP released version 2.1.5 to fix CVE-2026-4020, closing a medium-severity information disclosure flaw in the WordPress plugin. The patch addresses a bug...
JCE Pro 2.9.99.6 patch for CVE-2026-48907
Security Patch Release
H score46
First: 17.06.2026 13:09
Last: 17.06.2026 13:09
Sources 1
About this happening:
JCE security team released JCE Pro 2.9.99.6 in early June 2026 to fix CVE-2026-48907 in the Widget Factory Joomla Content Editor (JCE) plugin. The update addre...
JCE Pro 2.9.99.6 patch for CVE-2026-48907
Security Patch ReleaseAbout this happening: JCE security team released JCE Pro 2.9.99.6 in early June 2026 to fix CVE-2026-48907 in the Widget Factory Joomla Content Editor (JCE) plugin. The update addre...
Everest Forms Pro CVE-2026-3300 active exploitation wave
Exploitation Wave
H score87
First: 05.06.2026 11:38
Last: 05.06.2026 11:38
Sources 1
How related:
According to Wordfence data, active exploitation started on April 13, with the firewall blocking over 29,300 attempts.
About this happening:
Active exploitation of CVE-2026-3300 in Everest Forms Pro is driving complete site compromise risk for WordPress sites. Attackers have been using the flaw for arbitrar...
Everest Forms Pro CVE-2026-3300 active exploitation wave
Exploitation WaveHow related: According to Wordfence data, active exploitation started on April 13, with the firewall blocking over 29,300 attempts.
About this happening: Active exploitation of CVE-2026-3300 in Everest Forms Pro is driving complete site compromise risk for WordPress sites. Attackers have been using the flaw for arbitrar...
The vendor security patch release for CVE-2026-8206
Security Patch Release
H score89
First: 03.06.2026 01:12
Last: 03.06.2026 01:12
Sources 1
About this happening:
Kirki - Freeform Page Builder, Website Builder & Customizer shipped version 6.0.7 to fix CVE-2026-8206, a privilege-escalation flaw that could let attackers take over...
The vendor security patch release for CVE-2026-8206
Security Patch ReleaseAbout this happening: Kirki - Freeform Page Builder, Website Builder & Customizer shipped version 6.0.7 to fix CVE-2026-8206, a privilege-escalation flaw that could let attackers take over...
WP Maps Pro 6.1.1 security patch for CVE-2026-8732
Security Patch Release
H score49
First: 31.05.2026 17:06
Last: 31.05.2026 17:06
Sources 1
About this happening:
WP Maps Pro 6.1.1 was released to fix CVE-2026-8732, giving WordPress administrators a patch for a flaw that enabled unauthenticated administrator-account creation. Th...
WP Maps Pro 6.1.1 security patch for CVE-2026-8732
Security Patch ReleaseAbout this happening: WP Maps Pro 6.1.1 was released to fix CVE-2026-8732, giving WordPress administrators a patch for a flaw that enabled unauthenticated administrator-account creation. Th...
Timeline
-
06.06.2026 17:09 2 articles · 1mo ago
Everest Forms developer patches CVE-2026-3300 in Everest Forms Pro
Mitigation Patch UpdateThe Everest Forms developer releases a patch for CVE-2026-3300 in Everest Forms Pro on March 18, closing an unauthenticated arbitrary code execution flaw in versions 1.9.12 and earlier that can be triggered through the plugin’s Complex Calculation feature.
Show sources
- Critical Everest Forms Pro flaw exploited to take over WordPress sites — www.bleepingcomputer.com — 06.06.2026 17:09
- Critical Everest Forms Pro flaw exploited to take over WordPress sites — www.bleepingcomputer.com — 06.06.2026 17:09
-
06.06.2026 17:09 1 articles · 1mo ago
Attackers exploit CVE-2026-3300 to create rogue WordPress administrator accounts
Exploitation ObservedOn April 13, Wordfence telemetry shows active exploitation of CVE-2026-3300 against WordPress sites using Everest Forms Pro, with more than 29,300 blocked attempts and injected PHP code creating rogue administrator accounts such as 'diksimarina'.
Show sources
- Critical Everest Forms Pro flaw exploited to take over WordPress sites — www.bleepingcomputer.com — 06.06.2026 17:09
-
06.06.2026 17:09 1 articles · 1mo ago
Wordfence publishes indicators for CVE-2026-3300 exploitation in Everest Forms Pro
Detection Ioc UpdateWordfence publishes attacker indicators for CVE-2026-3300, saying exploitation attempts originate primarily from 202.56.2[.]126 and 209.146.60.26 and advising defenders to block them and review administrator accounts and logs for suspicious activity, especially entries containing 'diksimarina'.
Show sources
- Critical Everest Forms Pro flaw exploited to take over WordPress sites — www.bleepingcomputer.com — 06.06.2026 17:09