ch0k1 on Nostr: Hackers Exploit Critical Everest Forms Pro WordPress Plugin to Take Over Sites Threat ...
Hackers Exploit Critical Everest Forms Pro WordPress Plugin to Take Over Sites
https://thehackernews.com/2026/06/hackers-exploit-critical-everest-forms.htmlThreat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise.
The vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution bug impacting all versions of the plugin up to, and including, 1.9.12. A patch for the flaw was released on March 18, 2026, with version 1.9.13.
https://stacker.news/items/1502939Published at
2026-06-05 11:02:59 UTCEvent JSON
{
"id": "8d65cc571e47ebcac82c8a5db5bdfbeaa760664abc60caab79de34ae38220e37",
"pubkey": "b4403b2415a020c20691bb18c51ada5acb64b71d2f60966cb3c78ba683542d4e",
"created_at": 1780657379,
"kind": 1,
"tags": [
[
"client",
"stacker.news"
]
],
"content": "Hackers Exploit Critical Everest Forms Pro WordPress Plugin to Take Over Sites\nhttps://thehackernews.com/2026/06/hackers-exploit-critical-everest-forms.html\n\nThreat actors are actively exploiting a critical security flaw in Everest Forms Pro, a WordPress plugin with about 4,000 active installations, to execute arbitrary code, leading to a complete site compromise.\n\nThe vulnerability in question is CVE-2026-3300 (CVSS score: 9.8), a remote code execution bug impacting all versions of the plugin up to, and including, 1.9.12. A patch for the flaw was released on March 18, 2026, with version 1.9.13.\n\nhttps://stacker.news/items/1502939",
"sig": "44cae6d06408dac265c133c1cf0ddd98e6b8d3e1b6490a21bc1b6e4149819c356f5b284843d2d56f658887a3db71ed21ac42cc9e9b616fb17a4c28d19feb0d4e"
}