Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Vulnerability Exploited in WordPress Plugin

Critical Vulnerability Exploited in WordPress Plugin

Posted on June 4, 2026 By CWS

Hackers are currently exploiting a severe vulnerability in the Everest Forms Pro WordPress plugin, identified as CVE-2026-3300. This flaw, which has a critical CVSS score of 9.8, allows attackers to inject and execute arbitrary PHP code remotely on affected websites.

Details of the Exploitation

The vulnerability impacts all plugin versions up to 1.9.12. Even after a patch was released on March 18, 2026, exploitation campaigns began targeting unpatched systems on April 13, 2026. According to Wordfence, there have been over 29,300 blocked exploitation attempts, with a significant surge on May 16, recording more than 17,900 attacks.

The core issue lies within the plugin’s ‘Complex Calculation’ feature, specifically in the process_filter() function. This function constructs PHP code dynamically from user inputs and uses the risky eval() function without properly escaping critical characters, allowing code injection through form fields.

Observed Attack Patterns

Attackers have been utilizing this vulnerability to create unauthorized administrator accounts, commonly using the username ‘diksimarina.’ Once they gain admin access, they can upload malicious files, modify content, or further compromise the server environment.

Security data has identified several IP addresses involved in these exploits, generating thousands of malicious requests. Notable malicious IPs include 202.56.2[.]126 and 209.146.60[.]26, among others. These attacks primarily target the /wp-admin/admin-ajax.php endpoint with specially crafted POST requests.

Mitigation and Recommendations

This vulnerability poses a significant risk due to its ability to be exploited without authentication. Websites using Everest Forms Pro, particularly with the Complex Calculation feature active, are highly exposed. Wordfence users received early protection, but applying the official patch by updating to version 1.9.13 remains essential.

Administrators should update the plugin immediately, check for unauthorized admin accounts, and review server logs for suspicious activity. Indicators of compromise include new unknown admin users and requests from known malicious IPs.

Given the active exploitation and ease of attack, this vulnerability is a substantial threat to WordPress sites, underscoring the importance of timely updates and continuous monitoring.

Stay informed by following us on Google News, LinkedIn, and X for more updates.

Cyber Security News Tags:CVE-2026-3300, Cybersecurity, Everest Forms Pro, exploit prevention, PHP code injection, plugin vulnerability, remote code execution, web security, website security, Wordfence, WordPress

Post navigation

Previous Post: Critical Vulnerability in Mirasvit Cache Warmer Exposed
Next Post: FlutterShell Backdoor: New Threat on macOS via Ads

Related Posts

SmartApeSG Campaign Infects Windows with Remote Access Malware SmartApeSG Campaign Infects Windows with Remote Access Malware Cyber Security News
Six New Microsoft Vulnerabilities Added to CISA’s KEV List Six New Microsoft Vulnerabilities Added to CISA’s KEV List Cyber Security News
Cyber Attack via Prayer App Amid US-Israel Strikes on Iran Cyber Attack via Prayer App Amid US-Israel Strikes on Iran Cyber Security News
Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure Russian Hackers Attacking Network Edge Devices in Western Critical Infrastructure Cyber Security News
Cisco Unified Contact Center Express Vulnerabilities Let Remote Attacker Execute Malicious Code Cisco Unified Contact Center Express Vulnerabilities Let Remote Attacker Execute Malicious Code Cyber Security News
Linux Zero-Day Vulnerability Urges Immediate Patching Linux Zero-Day Vulnerability Urges Immediate Patching Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Google Gemini Vulnerability Allows Messaging Exploits
  • FlutterShell Backdoor: New Threat on macOS via Ads
  • Critical Vulnerability Exploited in WordPress Plugin
  • Critical Vulnerability in Mirasvit Cache Warmer Exposed
  • China-Linked TA4922 Broadens Cyber Attacks Globally

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Google Gemini Vulnerability Allows Messaging Exploits
  • FlutterShell Backdoor: New Threat on macOS via Ads
  • Critical Vulnerability Exploited in WordPress Plugin
  • Critical Vulnerability in Mirasvit Cache Warmer Exposed
  • China-Linked TA4922 Broadens Cyber Attacks Globally

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark