Close Menu

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    K-pop Fans Are Calling Out Creepy Deepfakes of Idols

    June 6, 2026

    CVE-2026-11441 | THREATINT

    June 6, 2026

    SSA-417547 V1.0: Multiple Vulnerabilities in INTRALOG WMS Before V4

    June 6, 2026
    Facebook X (Twitter) Instagram
    • Demos
    • Technology
    • Gaming
    • Buy Now
    Facebook X (Twitter) Instagram Pinterest Vimeo
    Canadian Cyber WatchCanadian Cyber Watch
    • Home
    • News
    • Alerts
    • Tips
    • Tools
    • Industry
    • Incidents
    • Events
    • Education
    Subscribe
    Canadian Cyber WatchCanadian Cyber Watch
    Home»News»Critical Everest Forms Pro flaw exploited to take over WordPress sites
    News

    Critical Everest Forms Pro flaw exploited to take over WordPress sites

    adminBy adminJune 6, 2026No Comments3 Mins Read
    Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
    Share
    Facebook Twitter LinkedIn Pinterest Email


    Critical Everest Forms Pro flaw exploited to take over WordPress sites

    Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, which lets them take complete control of a WordPress website.

    The security issue affects versions 1.9.12 and earlier of the plugin and can be leveraged without authentication to execute arbitrary code on the server.

    Everest Forms Pro is a commercial add-on for the WordPress form builder plugin Everest Forms. It is used to create contact, registration, payment, and other custom application forms.

    image

    The CVE-2026-3300 vulnerability is in the plugin’s Complex Calculation feature, which accepts values submitted through form fields and inserts them into a PHP code string. Then, it executes the resulting code using PHP’s ‘eval ()’ function.

    Although user input is passed through a ‘sanitize_text_field()’ function, which does not escape single quotes (‘) or other characters that influence PHP syntax.

    As a result, an attacker can close the intended string, inject arbitrary PHP code, and comment out the remaining generated code to achieve code execution on the server.

    Telemetry data from Wordfence firewall and malware scanner for WordPress shows that the vulnerability is being exploited in the wild to create rogue administrator accounts.

    “The attacker submits a value for a text field that begins with a single quote to close the wrapping string literal, followed by a PHP statement that calls wp_insert_user() to create a new administrator account with the username ‘diksimarina’,” explains a report from Wordfence.

    “The trailing // comment marker ensures the rest of the generated PHP code, including the closing quote, is treated as a comment and does not cause a syntax error.”

    “When the form is processed, and the calculation is evaluated, the injected PHP code is executed, and the malicious administrator account is created.”

    Administrator-level access gives attackers full power to perform high-risk actions on the breached website, including modifying content, installing plugins and themes, planting backdoors and webshells, and accessing private databases.

    Researcher h0xilo submitted the CVE-2026-3300 vulnerability through Wordfence in February, and on March 18, the Everest Forms developer released a patch that addresses the issue.

    According to Wordfence data, active exploitation started on April 13, with the firewall blocking over 29,300 attempts.

    Exploitation volume
    Exploitation volume
    Source: Wordfence

    Wordfence says exploitation attempts originate primarily from two IP addresses, 202.56.2[.]126 and 209.146.60.26, and recommends defenders block them.

    However, Wordfence’s report provides several offending IP addresses as indicators of compromise (IOCs).

    Website administrators are also recommended to review log files and administrator accounts for any suspicious activity, especially containing the string “diksimarina.”


    article image

    Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.

    The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.

    Get the whitepaper



    Source link

    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    Previous ArticleDebian Request Tracker 5 Key Privilege Escalation SQL Injection DSA-6324-1
    Next Article SSA-417547 V1.0: Multiple Vulnerabilities in INTRALOG WMS Before V4
    admin
    • Website

    Related Posts

    News

    K-pop Fans Are Calling Out Creepy Deepfakes of Idols

    June 6, 2026
    News

    Scientists Discover Hidden Symmetry on Earth That Nobody Can Explain

    June 6, 2026
    News

    The U.S. Military Quietly Turned GPS Into a Global ‘Numbers Station,’ Evidence Suggests

    June 6, 2026
    Add A Comment

    Comments are closed.

    Demo
    Top Posts

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202630 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews
    85
    Featured

    Pico 4 Review: Should You Actually Buy One Instead Of Quest 2?

    January 15, 2021 Featured
    8.1
    Uncategorized

    A Review of the Venus Optics Argus 18mm f/0.95 MFT APO Lens

    January 15, 2021 Uncategorized
    8.9
    Editor's Picks

    DJI Avata Review: Immersive FPV Flying For Drone Enthusiasts

    January 15, 2021 Editor's Picks

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Demo
    Most Popular

    Catchy & Intriguing

    March 17, 202674 Views

    IP Address Investigations and Local OSINT

    March 20, 202630 Views

    Defending Canada’s Digital Frontier: Combating Phishing, Social Engineering, Ransomware, and Malware

    March 23, 202629 Views
    Our Picks

    K-pop Fans Are Calling Out Creepy Deepfakes of Idols

    June 6, 2026

    CVE-2026-11441 | THREATINT

    June 6, 2026

    SSA-417547 V1.0: Multiple Vulnerabilities in INTRALOG WMS Before V4

    June 6, 2026

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Facebook X (Twitter) Instagram Pinterest
    • Home
    • Technology
    • Gaming
    • Phones
    • Buy Now
    © 2026 ThemeSphere. Designed by ThemeSphere.

    Type above and press Enter to search. Press Esc to cancel.