Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical Flaw in Everest Forms Plugin Threatens WordPress Sites

Critical Flaw in Everest Forms Plugin Threatens WordPress Sites

Posted on June 8, 2026 By CWS

WordPress site administrators are facing a significant security issue due to a vulnerability in the Everest Forms Pro plugin. This flaw, which has been actively exploited, allows unauthorized individuals to take control of websites. According to Defiant, a prominent security firm, this vulnerability has been used in attacks for several months.

Understanding the Everest Forms Vulnerability

Everest Forms, a popular plugin used by over 100,000 WordPress sites to create various types of forms, is at the center of this security threat. The vulnerability, identified as CVE-2026-3300 with a CVSS score of 9.8, permits remote attackers to inject PHP code into form fields via the Complex Calculation feature.

Despite the plugin’s efforts to sanitize inputs, a specific function fails to properly escape certain characters, allowing malicious code to be executed on the server. This enables attackers to inject and run arbitrary PHP code by manipulating form fields such as text, email, or URL when utilizing the affected feature.

Exploitation and Consequences

The exploitation of this vulnerability can lead to severe consequences, including the creation of unauthorized administrative accounts and the deployment of web shells. These actions grant attackers full control over compromised WordPress sites, jeopardizing the security and integrity of the affected websites.

Defiant reports that the vulnerability was first addressed in Everest Forms Pro version 1.9.13, released in March. However, exploitation attempts have persisted, with the first known attack occurring on April 13. To date, more than 29,000 exploit attempts have been blocked by the security firm.

Recommendations for WordPress Users

WordPress site owners using Everest Forms Pro are strongly advised to update to version 1.9.13 or later immediately. Additionally, they should check for unauthorized administrative accounts, especially those named ‘diksimarina’ or using the email ‘[email protected]’.

Staying vigilant and keeping plugins updated are crucial steps in safeguarding WordPress sites against similar threats. As vulnerabilities continue to emerge, proactive security measures are essential to protect online assets.

Related security concerns in WordPress plugins such as Kirki, Burst Statistics, and WP Maps Pro have also been highlighted, emphasizing the need for ongoing diligence in maintaining website security.

For more information on protecting your WordPress site and the latest security updates, visit the official WordPress security page regularly.

Security Week News Tags:admin account, CVE-2026-3300, Defiant warnings, Everest Forms, PHP code injection, plugin vulnerability, security update, site takeover, web shell, WordPress security

Post navigation

Previous Post: OWASP Unveils AI Security Report for Enhanced Protection
Next Post: UniFi OS Server Vulnerability Allows Root Access

Related Posts

Tennessee Hospital Data Breach Exposes Thousands Tennessee Hospital Data Breach Exposes Thousands Security Week News
Cisco Addresses Critical Flaw in Secure Workload Cisco Addresses Critical Flaw in Secure Workload Security Week News
QNAP Patches Vulnerabilities Exploited at Pwn2Own Ireland QNAP Patches Vulnerabilities Exploited at Pwn2Own Ireland Security Week News
SASE Company Netskope Files for IPO SASE Company Netskope Files for IPO Security Week News
From Tech Podcasts to Policy: Trump’s New AI Plan Leans Heavily on Silicon Valley Industry Ideas From Tech Podcasts to Policy: Trump’s New AI Plan Leans Heavily on Silicon Valley Industry Ideas Security Week News
Critical Vulnerabilities in SolarWinds Serv-U Addressed Critical Vulnerabilities in SolarWinds Serv-U Addressed Security Week News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Security Concerns Rise with AI-Driven Vibe Coding
  • The Emerging Threat of Mythos in Open Source
  • UNC3753 Targets US Law Firms with Vishing Tactics
  • Lansing College Data Breach Affects 174,000 Individuals
  • Critical Check Point VPN Vulnerability Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Security Concerns Rise with AI-Driven Vibe Coding
  • The Emerging Threat of Mythos in Open Source
  • UNC3753 Targets US Law Firms with Vishing Tactics
  • Lansing College Data Breach Affects 174,000 Individuals
  • Critical Check Point VPN Vulnerability Exploited

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark