connect24h[verified]@connect24hActive Exploitation
The post alerts that CVE‑2026‑3300 in Everest Forms Pro is actively exploited to fully takeover WordPress sites, urging organizations to act before a PoC spreads.
Kruptos[verified]@KuptoKosmosActive Exploitation
The post confirms that CVE-2026-3300 is being actively exploited against the Everest Forms Pro plugin, with thousands of attacks reported, while a patch has already been released.
Rıdvan Yağlı[verified]@ridvanyagliActive Exploitation
The post lists CVEs that attackers reportedly use to target WordPress and Joomla systems, indicating ongoing exploitation of these vulnerabilities.
Teegra 🧝♀️𝕏[verified]@TeeegraActive Exploitation
The post reports that hackers are actively exploiting CVE‑2026‑3300 in Everest Forms Pro, enabling unauthenticated remote code execution through the eval function in the Complex Calculation feature; no patches or workaround are mentioned.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
CVE-2026-3300 in Everest Forms Pro WordPress plugin is being actively exploited with PHP code injection via form fields, enabling immediate site compromise; the vulnerability is patched in version 1.9.13.
モーくん🐮|WordPress × セキュリティ[verified]@accell_mo_kunActive Exploitation
More than 29,000 attacks have been detected against sites running the unpatched Everest Forms Pro, prompting an immediate update to 1.9.13.
嶋田大貴[verified]@shimarinGeneral
The post references CVE-2026-3300 in a general remark about WordPress sanitation issues but provides no technical, exploit, or mitigation details.
🍫ゆきの🌗☕️[verified]@wizyigActive Exploitation
The post confirms that CVE-2026-3300, a CVSS 9.8 RCE in Everest Forms Pro, is being actively exploited with over 29,000 recorded attack attempts, and a March patch (1.9.13) is available.