Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Critical WordPress Plugin Flaw Exploited by Hackers

Critical WordPress Plugin Flaw Exploited by Hackers

Posted on June 5, 2026 By CWS

Cybersecurity experts have reported active exploitation of a severe vulnerability in the Everest Forms Pro WordPress plugin, threatening over 4,000 installations. The flaw allows attackers to execute arbitrary code, potentially leading to full site control.

Details of the Security Flaw

The vulnerability, identified as CVE-2026-3300, is a remote code execution issue affecting all plugin versions up to 1.9.12. With a CVSS score of 9.8, this critical flaw was addressed with a patch released on March 18, 2026, in version 1.9.13.

According to Wordfence, the issue stems from the Calculation Addon’s process_filter() function, which inadequately escapes user inputs before executing them as PHP code. This oversight allows attackers to inject harmful code via any form field using the ‘Complex Calculation’ feature.

Exploitation Impact and Observations

Successful exploitation can enable unauthorized individuals to run PHP code on the server, create false administrator accounts, and deploy malicious software. Wordfence reported that since April 13, 2026, over 29,300 exploit attempts have been blocked, with 16 attempts occurring in the past day alone.

Attackers typically aim to establish an administrator account under the name ‘diksimarina’ using specific IP addresses, underscoring the need for heightened vigilance among site administrators.

Broader Cybersecurity Concerns

The report coincides with a warning from Sansec about skimmer campaigns leveraging Stripe as a covert command-and-control server. By exploiting trusted domains like Stripe and Google Tag Manager, attackers can bypass security filters to steal sensitive customer data from e-commerce platforms.

One such campaign, GorgonAgora, utilizes counterfeit .shop sites to impersonate major brands and siphon card information to a centralized server in Moldova. This operation highlights the sophistication and scale of modern cyber threats.

In conclusion, the exploitation of the Everest Forms Pro plugin and similar campaigns underscore the importance of regular security updates and vigilant monitoring of web applications. As cyber threats evolve, staying informed and proactive is critical for protecting online assets.

The Hacker News Tags:Cybersecurity, Everest Forms Pro, Hackers, plugin vulnerability, remote code execution, Sansec, Security, site compromise, Wordfence, WordPress

Post navigation

Previous Post: Critical Microsoft Edge Flaw Enables Remote Code Execution
Next Post: Chinese Spies Exploit Fake Job Offers to Extract Sensitive Data

Related Posts

Apple Widens iOS 18.7.7 Update to Shield Against DarkSword Apple Widens iOS 18.7.7 Update to Shield Against DarkSword The Hacker News
GPT-5 Agent That Finds and Fixes Code Flaws Automatically GPT-5 Agent That Finds and Fixes Code Flaws Automatically The Hacker News
GitHub Actions Compromised to Steal CI/CD Credentials GitHub Actions Compromised to Steal CI/CD Credentials The Hacker News
New ZuRu Malware Variant Targeting Developers via Trojanized Termius macOS App New ZuRu Malware Variant Targeting Developers via Trojanized Termius macOS App The Hacker News
Researchers Expose GhostCall and GhostHire: BlueNoroff’s New Malware Chains Researchers Expose GhostCall and GhostHire: BlueNoroff’s New Malware Chains The Hacker News
SolarWinds WHD Exploited in Complex Multi-Stage Cyber Attacks SolarWinds WHD Exploited in Complex Multi-Stage Cyber Attacks The Hacker News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies
  • Android Spyware Asin Targets Arabic Users via Fake Apps
  • Microsoft 365 Resolves Driver Auto-Update Bypass Issue
  • Malicious Extensions Target AI Chat Platforms Users
  • Reaper Malware Threatens Mac Users with Browser and Wallet Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • OWASP Project Enhances Security by Identifying Vulnerable Dependencies
  • Android Spyware Asin Targets Arabic Users via Fake Apps
  • Microsoft 365 Resolves Driver Auto-Update Bypass Issue
  • Malicious Extensions Target AI Chat Platforms Users
  • Reaper Malware Threatens Mac Users with Browser and Wallet Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark