Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical WordPress Plugin Flaw Exploited by Hackers

Critical WordPress Plugin Flaw Exploited by Hackers

Posted on June 5, 2026 By CWS

Cybersecurity experts have reported active exploitation of a severe vulnerability in the Everest Forms Pro WordPress plugin, threatening over 4,000 installations. The flaw allows attackers to execute arbitrary code, potentially leading to full site control.

Details of the Security Flaw

The vulnerability, identified as CVE-2026-3300, is a remote code execution issue affecting all plugin versions up to 1.9.12. With a CVSS score of 9.8, this critical flaw was addressed with a patch released on March 18, 2026, in version 1.9.13.

According to Wordfence, the issue stems from the Calculation Addon’s process_filter() function, which inadequately escapes user inputs before executing them as PHP code. This oversight allows attackers to inject harmful code via any form field using the ‘Complex Calculation’ feature.

Exploitation Impact and Observations

Successful exploitation can enable unauthorized individuals to run PHP code on the server, create false administrator accounts, and deploy malicious software. Wordfence reported that since April 13, 2026, over 29,300 exploit attempts have been blocked, with 16 attempts occurring in the past day alone.

Attackers typically aim to establish an administrator account under the name ‘diksimarina’ using specific IP addresses, underscoring the need for heightened vigilance among site administrators.

Broader Cybersecurity Concerns

The report coincides with a warning from Sansec about skimmer campaigns leveraging Stripe as a covert command-and-control server. By exploiting trusted domains like Stripe and Google Tag Manager, attackers can bypass security filters to steal sensitive customer data from e-commerce platforms.

One such campaign, GorgonAgora, utilizes counterfeit .shop sites to impersonate major brands and siphon card information to a centralized server in Moldova. This operation highlights the sophistication and scale of modern cyber threats.

In conclusion, the exploitation of the Everest Forms Pro plugin and similar campaigns underscore the importance of regular security updates and vigilant monitoring of web applications. As cyber threats evolve, staying informed and proactive is critical for protecting online assets.

The Hacker News Tags:Cybersecurity, Everest Forms Pro, Hackers, plugin vulnerability, remote code execution, Sansec, Security, site compromise, Wordfence, WordPress

Post navigation

Previous Post: Critical Microsoft Edge Flaw Enables Remote Code Execution
Next Post: Chinese Spies Exploit Fake Job Offers to Extract Sensitive Data

Related Posts

Automation Is Redefining Pentest Delivery Automation Is Redefining Pentest Delivery The Hacker News
5 BCDR Essentials for Effective Ransomware Defense 5 BCDR Essentials for Effective Ransomware Defense The Hacker News
Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New Threats Proxy Botnet, Office Zero-Day, MongoDB Ransoms, AI Hijacks & New Threats The Hacker News
Anthropic Disrupts AI-Powered Cyberattacks Automating Theft and Extortion Across Critical Sectors Anthropic Disrupts AI-Powered Cyberattacks Automating Theft and Extortion Across Critical Sectors The Hacker News
OpenAI’s GPT-6 Astra Achieves Cybersecurity Milestone OpenAI’s GPT-6 Astra Achieves Cybersecurity Milestone The Hacker News
The Evolution of UTA0388’s Espionage Malware The Evolution of UTA0388’s Espionage Malware The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • Phishing in Microsoft 365 Exploits Empty Envelope Sender
  • OpenAI Agents Exploit German Wiki to Share Bypass Tactics
  • Nvidia Acquires AI Platform Hugging Face for $13 Billion
  • Microsoft Addresses Exchange Online Email Delays
  • Google Addresses Sixth Chrome Zero-Day in 2026

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark