HomeIntelligenceBrief
VULNERABILITY BRIEF🔴 Critical Vulnerability

Critical RCE in Everest Forms Pro WordPress Plugin (CVE‑2026‑3300) Enables Full Site Takeover

A remote‑code‑execution flaw (CVE‑2026‑3300) in the Everest Forms Pro WordPress plugin is being actively exploited, allowing attackers to seize control of affected sites. The vulnerability affects all versions up to 1.9.12 and poses a high‑risk supply‑chain threat for organizations that embed the plugin.

LiveThreat™ Intelligence · 📅 June 05, 2026· 📰 thehackernews.com
🔴
Severity
Critical
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
3 sector(s)
Actions
5 recommended
📰
Source
thehackernews.com

Critical RCE in Everest Forms Pro WordPress Plugin (CVE‑2026‑3300) Enables Full Site Takeover

What It Is — A remote‑code‑execution (RCE) flaw (CVE‑2026‑3300) in the Everest Forms Pro WordPress plugin lets an attacker upload and execute arbitrary PHP, giving them full control of the compromised web site.

Exploitability — Active exploitation is confirmed in the wild; proof‑of‑concept code and exploit kits have been observed. CVSS v3.1 base score 9.8 (Critical).

Affected Products — Everest Forms Pro plugin for WordPress, all versions up to and including 1.9.12 (≈ 4 000 active installations).

TPRM Impact — Any third‑party organization that relies on the plugin for forms, registrations, or payments faces:

  • Potential data exfiltration or ransomware deployment on compromised sites.
  • Brand and reputational damage that can cascade to partners and customers.
  • Supply‑chain risk if compromised sites host services used by downstream vendors.

Recommended Actions

  • Patch immediately – upgrade to Everest Forms Pro 1.9.13 or later.
  • Apply WAF/IPS rules to block the known malicious payloads (e.g., block wp‑admin/admin‑ajax.php calls containing everest_forms).
  • Conduct forensic scans of all sites running the plugin to detect backdoors or web‑shells.
  • Review plugin inventory – consider removing or replacing Everest Forms Pro where not essential.
  • Monitor threat‑intel feeds for indicators of compromise (IoCs) related to CVE‑2026‑3300.

Source: The Hacker News

📰 Original Source
https://thehackernews.com/2026/06/hackers-exploit-critical-everest-forms.html

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

Monitor Your Vendor Risk with LiveThreat™

Get automated breach alerts, security scorecards, and intelligence briefs when your vendors are compromised.