Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical WordPress Plugin Flaw Exploited by Hackers

Critical WordPress Plugin Flaw Exploited by Hackers

Posted on June 5, 2026 By CWS

Cybersecurity experts have reported active exploitation of a severe vulnerability in the Everest Forms Pro WordPress plugin, threatening over 4,000 installations. The flaw allows attackers to execute arbitrary code, potentially leading to full site control.

Details of the Security Flaw

The vulnerability, identified as CVE-2026-3300, is a remote code execution issue affecting all plugin versions up to 1.9.12. With a CVSS score of 9.8, this critical flaw was addressed with a patch released on March 18, 2026, in version 1.9.13.

According to Wordfence, the issue stems from the Calculation Addon’s process_filter() function, which inadequately escapes user inputs before executing them as PHP code. This oversight allows attackers to inject harmful code via any form field using the ‘Complex Calculation’ feature.

Exploitation Impact and Observations

Successful exploitation can enable unauthorized individuals to run PHP code on the server, create false administrator accounts, and deploy malicious software. Wordfence reported that since April 13, 2026, over 29,300 exploit attempts have been blocked, with 16 attempts occurring in the past day alone.

Attackers typically aim to establish an administrator account under the name ‘diksimarina’ using specific IP addresses, underscoring the need for heightened vigilance among site administrators.

Broader Cybersecurity Concerns

The report coincides with a warning from Sansec about skimmer campaigns leveraging Stripe as a covert command-and-control server. By exploiting trusted domains like Stripe and Google Tag Manager, attackers can bypass security filters to steal sensitive customer data from e-commerce platforms.

One such campaign, GorgonAgora, utilizes counterfeit .shop sites to impersonate major brands and siphon card information to a centralized server in Moldova. This operation highlights the sophistication and scale of modern cyber threats.

In conclusion, the exploitation of the Everest Forms Pro plugin and similar campaigns underscore the importance of regular security updates and vigilant monitoring of web applications. As cyber threats evolve, staying informed and proactive is critical for protecting online assets.

The Hacker News Tags:Cybersecurity, Everest Forms Pro, Hackers, plugin vulnerability, remote code execution, Sansec, Security, site compromise, Wordfence, WordPress

Post navigation

Previous Post: Critical Microsoft Edge Flaw Enables Remote Code Execution
Next Post: Chinese Spies Exploit Fake Job Offers to Extract Sensitive Data

Related Posts

Microsoft Fixes 59 Security Flaws, Including Six Critical Zero-Days Microsoft Fixes 59 Security Flaws, Including Six Critical Zero-Days The Hacker News
Cisco Patches Actively Exploited SD-WAN Vulnerability Cisco Patches Actively Exploited SD-WAN Vulnerability The Hacker News
Masjesu Botnet: Global Threat to IoT Devices Masjesu Botnet: Global Threat to IoT Devices The Hacker News
Apple Urges iOS Update to Combat Exploit Kit Threats Apple Urges iOS Update to Combat Exploit Kit Threats The Hacker News
Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt Iran-Linked Hackers Mapped Ship AIS Data Days Before Real-World Missile Strike Attempt The Hacker News
The Emerging Threat of Mythos in Open Source The Emerging Threat of Mythos in Open Source The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Qilin Ransomware Surges with 1,358 Victims Worldwide
  • Cloud Tenants Could Threaten Power Grids Without Exploits
  • Fake Game Downloads Deliver Multi-Stage Infostealers
  • Apple Resolves Hide My Email Security Flaw
  • Google Unveils Gemini 3.5 Flash Cyber for Faster Vulnerability Fixes

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark