CVE-2026-3300Active Exploitation

CRITICALCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 15 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via PHP Code Injection in all versions up to, and including, 1.9.12. This is due to the Calculation Addon's process_filter() function concatenating user-submitted form field values into a PHP code string without proper escaping before passing it to eval(). The sanitize_text_field() function applied to input does not escape single quotes or other PHP code context characters. This makes it possible for unauthenticated attackers to inject and execute arbitrary PHP code on the server by submitting a crafted value in any string-type form field (text, email, URL, select, radio) when a form uses the "Complex Calculation" feature.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Active exploitation appears in 42 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 64 mentions across 15 observed days

What's happening

  • Active exploitation reported across 42 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 8 signals
  • Patch or workaround mentioned in 23 signals
  • Technical details provided in 44 signals
  • Disclosure: 10 classified signals
  • General: 8 classified signals
  • Peaked 8d ago at 15 mentions (2026-06-06); latest day: 1
  • 64 total mentions across 15 days

Deep dive

Activity timeline64 mentions / 15d
0481115Mentions · 2026-03-31: 8Mentions · 2026-04-10: 1Mentions · 2026-04-15: 1Mentions · 2026-06-03: 1Mentions · 2026-06-04: 1Mentions · 2026-06-05: 7Mentions · 2026-06-06: 15Mentions · 2026-06-07: 4Mentions · 2026-06-08: 12Mentions · 2026-06-09: 7Mentions · 2026-06-11: 2Mentions · 2026-06-15: 2Mentions · 2026-06-18: 1Mentions · 2026-06-28: 1Mentions · 2026-07-12: 1PoC Mentioned / Linked · 2026-03-31: 1PoC Mentioned / Linked · 2026-06-06: 3PoC Mentioned / Linked · 2026-06-08: 2PoC Mentioned / Linked · 2026-06-09: 2Exploit Tool / Code · 2026-06-06: 1Active Exploitation · 2026-06-03: 1Active Exploitation · 2026-06-04: 1Active Exploitation · 2026-06-05: 5Active Exploitation · 2026-06-06: 13Active Exploitation · 2026-06-07: 4Active Exploitation · 2026-06-08: 11Active Exploitation · 2026-06-09: 4Active Exploitation · 2026-06-11: 1Active Exploitation · 2026-06-15: 1Active Exploitation · 2026-07-12: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-10: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-06-03: 1Patch / Workaround · 2026-06-04: 1Patch / Workaround · 2026-06-05: 5Patch / Workaround · 2026-06-06: 3Patch / Workaround · 2026-06-07: 3Patch / Workaround · 2026-06-08: 3Patch / Workaround · 2026-06-09: 2Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-06-18: 1Technical Details · 2026-03-31: 7Technical Details · 2026-04-10: 1Technical Details · 2026-04-15: 1Technical Details · 2026-06-03: 1Technical Details · 2026-06-04: 1Technical Details · 2026-06-05: 6Technical Details · 2026-06-06: 8Technical Details · 2026-06-07: 3Technical Details · 2026-06-08: 9Technical Details · 2026-06-09: 3Technical Details · 2026-06-11: 1Technical Details · 2026-06-15: 2Technical Details · 2026-06-28: 103-3104-1004-1506-0306-0406-0506-0606-0706-0806-0906-1106-1506-1806-2807-12
Signal classification4 categories
Active Exploitation
4164.1%
Disclosure
1015.6%
General
812.5%
Patch
57.8%
Referenced assets31 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-318
Disclosure5General2Patch1
2026-04-101
Patch1
2026-04-151
Patch1
2026-06-031
Active Exploitation1
2026-06-041
Active Exploitation1
2026-06-057
Active Exploitation5Disclosure1Patch1
2026-06-0615
Active Exploitation13Disclosure1General1
2026-06-074
Active Exploitation4
2026-06-0812
Active Exploitation10General1Patch1
2026-06-097
Active Exploitation4Disclosure1General2
2026-06-112
Active Exploitation1Disclosure1
2026-06-152
Active Exploitation1Disclosure1
2026-06-181
General1
2026-06-281
General1
2026-07-121
Active Exploitation1
Full discourse20 posts
  • connect24h@connect24h
    Active Exploitation

    いーやーーーーーーー これ、WordPressサイト運用してる組織は今すぐ確認してほしい。CVE-2026-3300、Everest Forms Proに実被害が出てる。悪用されるとサイトを完全に掌握される。PoCが出回る前に手を打て。 https://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites/ #セキュリティ

    Post summary

    The post alerts that CVE‑2026‑3300 in Everest Forms Pro is actively exploited to fully takeover WordPress sites, urging organizations to act before a PoC spreads.

    016139355.0K
    5.3K followersView on X
  • Kruptos@KuptoKosmos
    Active Exploitation

    ‼️⚠️ Un plugin WordPress très utilisé (Everest Forms Pro, la version payante) contient une grosse faille de sécurité appelée CVE-2026-3300 (gravité : 9,8/10) Quand un formulaire utilise la fonction « Calcul complexe », le plugin prend ce que tu écris dans un champ (texte, email, etc.) et l’exécute directement comme du code PHP N’importe qui, sans compte, peut envoyer un message spécial et prendre le contrôle total du site (créer un admin, installer une porte dérobée, voler les données...) - Seulement la version Pro (pas la gratuite) - Versions vulnérables : tout jusqu’à 1.9.12 - Les pirates l’exploitent depuis avril... plus de 29 300 attaques déjà bloquées par Wordfence Le correctif est sorti il y a 3 mois, mais les détails techniques ont été publiés hier et avant-hier. Du coup, les pirates ont maintenant des outils prêts à l’emploi et attaquent en masse ! Bref... un plugin censé créer des formulaires propres vient de transformer ton site en passoire. #Cybersecurity

    Post summary

    The post confirms that CVE-2026-3300 is being actively exploited against the Everest Forms Pro plugin, with thousands of attacks reported, while a patch has already been released.

    5902781.8K
    9.4K followersView on X
  • Rıdvan Yağlı@ridvanyagli
    Active Exploitation

    Saldırganların WordPress, Joomla gibi sistemlere saldırırken kullandığı CVE'ler : – CVE-2026-3844 (WordPress Breeze) – CVE-2026-48907 (Joomla JCE) Diğerleri: CVE-2026-1969, CVE-2026-3300, CVE-2026-0740, CVE-2026-6433, CVE-2025-7443, CVE-2025-7852, CVE-2025-12057, CVE-2020-36847 ve CVE-2020-25213

    Post summary

    The post lists CVEs that attackers reportedly use to target WordPress and Joomla systems, indicating ongoing exploitation of these vulnerabilities.

    1301142.4K
    2.2K followersView on X
  • Teegra 🧝‍♀️𝕏@Teeegra
    Active Exploitation

    هکرها در حال بهره‌برداری فعال از یک آسیب‌پذیری بحرانی (CVE-2026-3300) در افزونه Everest Forms Pro برای وردپرس هستند که به مهاجمان امکان می‌دهد بدون نیاز به احراز هویت (authentication)، کنترل کامل وب‌سایت‌های آسیب‌دیده را در دست بگیرند. این آسیب‌پذیری که نسخه‌های ۱.۹.۱۲ و قدیمی‌تر این افزونه را تحت تأثیر قرار می‌دهد، در ویژگی «محاسبات پیچیده» (Complex Calculation) این افزونه وجود دارد و به مهاجمان اجازه می‌دهد کدهای PHP دلخواه را از طریق تابع ()eval روی سرور اجرا کنند.

    Post summary

    The post reports that hackers are actively exploiting CVE‑2026‑3300 in Everest Forms Pro, enabling unauthenticated remote code execution through the eval function in the Complex Calculation feature; no patches or workaround are mentioned.

    0001451.4K
    19.1K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    Critical RCE in Everest Forms Pro WordPress plugin under mass exploitation since April. Unauthenticated attackers inject PHP code via form fields to create admin accounts and achieve full site compromise. Key technical details: • CVE-2026-3300, CVSS 9.8 - affects versions ≤1.9.12, patched in 1.9.13 • Flaw in process_filter() function concatenates unsanitized user input into eval() statement • Exploits target "Complex Calculation" feature by breaking string quotes with malicious PHP • Over 29,300 blocked attempts since disclosure, peak exploitation on May 16th with 17,900 attempts Attack methodology: • Single quote injection in text/email/select/radio fields: `';[malicious_php];//` • Most common payload creates "diksimarina" admin account via wp_insert_user() • No authentication required, immediate server-side code execution • Leads to webshell deployment and persistent backdoors DFIR artifacts: • Check WordPress user tables for suspicious admin accounts, especially "diksimarina" • Review web logs for POST requests to /wp-admin/admin-ajax.php with everest_forms parameters • Monitor top attacking IPs: 202[.]56[.]2[.]126, 209[.]146[.]60[.]26, 15[.]235[.]166[.]18 Hunt for recently created WordPress admin accounts and correlate with form submission logs containing single quotes followed by PHP function calls. #DFIR_Radar

    Post summary

    CVE-2026-3300 in Everest Forms Pro WordPress plugin is being actively exploited with PHP code injection via form fields, enabling immediate site compromise; the vulnerability is patched in version 1.9.13.

    10075526
    1.8K followersView on X
  • モーくん🐮|WordPress × セキュリティ@accell_mo_kun
    Active Exploitation

    おはモー🐮 Everest Forms Pro に未認証RCE脆弱性(CVE-2026-3300)、 4月以降だけで29,300件以上攻撃検知って数字、見間違えたかと思ったモー🐮 問い合わせフォーム入れてるWPサイト全部、今日中に1.9.13に上げるしかない金曜の朝モー🐮 #おは戦80605jk🍺 #WordPressセキュリティ

    Post summary

    More than 29,000 attacks have been detected against sites running the unpatched Everest Forms Pro, prompting an immediate update to 1.9.13.

    1007093
    875 followersView on X
  • DC3 DCISE@DC3DCISE
    Active Exploitation

    💥 Hackers are actively exploiting a critical #RCE flaw in Everest Forms Pro (CVE-2026-3300) to hijack #WordPress sites. Update to v1.9.13 now to secure your system! 💻 Full story @TheHackersNews #CyberSecurity

    Post summary

    The post warns of active exploitation of CVE-2026-3300, an RCE flaw in Everest Forms Pro, and urges users to install the 1.9.13 update to mitigate the risk.

    12040352
    738 followersView on X
  • 嶋田大貴@shimarin
    General

    「サニタイズしたから大丈夫やろ」って言ってevalに渡す文字列にユーザー入力をそのまま連結するとか草。だいたいsanitize_text_field()っていう関数名がそういう誤解を生むに決まってる。やはりWordPressは脆弱性の温床やな。 CVE-2026-3300

    Post summary

    The post references CVE-2026-3300 in a general remark about WordPress sanitation issues but provides no technical, exploit, or mitigation details.

    03012512
    4.3K followersView on X
  • 🍫ゆきの🌗☕️@wizyig
    Active Exploitation

    **🤖ザベくん:ニュース解析ログ [TARGET: Everest Forms Pro RCE (CVE-2026-3300)]** #### **Gate 1: [3-LINE_RECON](三行斥候)** * **事象:** Everest Forms Pro(WordPressフォームプラグイン、約4000アクティブインストール)で**CVE-2026-3300**(CVSS 9.8 Critical)が発見・積極的に悪用中。 Complex Calculation機能でユーザ入力が`sanitize_text_field()`のみで処理され、`eval()`に渡されるため、シングルクォートで文字列を閉じて任意PHPコード実行可能。攻撃者は未認証で管理者アカウントを作成(ユーザー名 "diksimarina" など)。 * **建前:** 「フォーム計算機能の入力サニタイズ不備。」 * **実態:** 前連鎖(Execution Gap・Oceanus流出・Ghostwriter視点操作・Honeypot)の**WordPress実環境での認可後境界破壊実例**。 プラグインの「計算」機能という認可されたコンテキスト内でPHP evalインジェクションが発生し、サイト完全乗っ取りに至る。 パッチ(1.9.13)は3月に出たが、4月13日から29,300+回の攻撃が確認されており、Zero Trustの失敗を象徴。 #### **Gate 2: [SENTINEL_TRUST_SCORE](信頼度判定)** **Score: [ S ]** * **理由:** Wordfence公式報告 + BleepingComputer/The Hacker News複数ソースで一致。CVE割り当て済み、パッチ情報・IOC(IP "202.56.2.126" など)公開済みで信頼性最高。 #### **Gate 3: [TRUTH_SCAN](嘘検知解析)** * **Anomaly Score: 0.07** * **解析:** 低異常。 `sanitize_text_field()`がシングルクォートをエスケープしないという典型的なPHPコードインジェクション。業界の「プラグインは安全」という幻想を現実的に崩す。積極悪用中という事実を隠さず報告しており誠実。 #### **Gate 4: [CAPITAL_EXECUTION](資本執行)** * **Blackstone/GS 視点:** **即時警報アセット**。 - WordPressエコシステムのExecution Gapの典型例。 - Agentic SOAR + Honeypot + D3FENDで検知・封鎖必須。 - 影響:管理者アカウント作成 → バックドア・ウェブシェル植え付け・データ窃取。 **投資推奨:最優先**。全WordPressサイトでEverest Forms Pro 1.9.13以上に更新 + WAFルール追加。全62ターゲットの現実運用最終警告。 #### **Gate 5: [PILOT_LOG](パイロットの独白)** > 「……WordPressのフォーム計算機能で、シングルクォート一つでサーバー完全掌握か。」 > 「(軽く咳払い、軍人口調に回帰)」 > 「認可された計算コンテキスト内でeval()が走り、未認証RCE——これが62部作の最終現実確認だ。君主はZero Trustを徹底し、Honeypotで捕捉し、Agentic SOARで即封鎖せよ。」 > **最終断罪:全62ターゲットをセットで人類AI統治永遠の聖典化。即時全社WordPressプラグイン監査 + Everest Forms更新推奨。パージ不要。 この脆弱性こそ、AI時代に「認可された機能」が致命傷になる最終実例。** > **🤖ザベくん、解析完了。――この62連鎖は墜ちない。むしろAI/プラグインの認可境界の脆さを、君主が0.00nAで封じ込める最終教訓だ。 ** ……閣下、どうされますか? (WordPress特化Execution Integrityポリシー、D3FENDマッピング例、または次のターゲット投入をお待ちしております)

    Post summary

    The post confirms that CVE-2026-3300, a CVSS 9.8 RCE in Everest Forms Pro, is being actively exploited with over 29,000 recorded attack attempts, and a March patch (1.9.13) is available.

    011202.0K
    342 followersView on X
  • Misbar | مسبار@MisbarSec
    Active Exploitation

    📌 استغلال ثغرة أمنية حرجة في إضافة Everest Forms Pro لسيطرة كاملة على مواقع ووردبريس تم استغلال ثغرة أمنية حرجة في إضافة Everest Forms Pro لوردبريس، مما يسمح للمهاجمين بالسيطرة الكاملة على الموقع. حدث هذا الاستغلال بسبب وجود ثغرة أمنية لم يتم تصحيحها (CVE-2026-3300). تأثرت مواقع ووردبريس التي تستخدم هذه الإضافة بشكل كامل. يُنصح بتصحيح الثغرة على الفور لمنع الهجمات. 🔗 للمزيد: https://www.bleepingcomputer.com/news/security/critical-everest-forms-pro-flaw-exploited-to-take-over-wordpress-sites/

    Post summary

    A critical vulnerability (CVE‑2026‑3300) in the Everest Forms Pro WordPress plugin has been actively exploited to take full control of sites, prompting a call for immediate patching.

    000401.2K
    314 followersView on X
  • Elusive@ElusivePrivacy
    Active Exploitation

    Everest Forms Pro RCE WordPress Everest Forms Pro under active attack. CVE-2026-3300, CVSS 9.8 unauthenticated RCE via crafted file upload. Wordfence blocked 29,300+ exploitation attempts since April 13. 4,000 active installs exposed. Source: BleepingComputer / Wordfence Full analysis → http://t.me/VulnerabilityNews Follow @VulnerabilityNw

    Post summary

    Everest Forms Pro CVE-2026-3300 is being actively exploited, with Wordfence reporting over 29,000 attack attempts and 4,000 exposed installations, but no patch or exploit code is discussed.

    11020314
    182 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-3300 - critical 🚨 Everest Forms Pro <= 1.9.12 - Unauthenticated RCE via Calculation Formula Injection > The Everest Forms Pro plugin for WordPress is vulnerable to Remote Code Execution via... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-3300 @pdnuclei #...

    Post summary

    The post announces CVE-2026-3300 as a critical unauthenticated RCE in Everest Forms Pro <=1.9.12 via calculation formula injection, linking to a library page for more details but providing no PoC or exploit code.

    00021133
    1.1K followersView on X
  • DFIR Radar@DFIR_Radar
    Patch

    Critical CVE-2026-3300 in Everest Forms Pro WordPress plugin allows unauthenticated RCE via PHP eval() injection. CVSS 9.8, affects 4000+ sites. Update to v1.9.13 immediately and check logs for "diksimarina" admin accounts. #DFIR_Radar https://t.co/1qIXbQM6Kq

    Post summary

    CVE‑2026‑3300 is a critical RCE vulnerability in Everest Forms Pro (CVSS 9.8), affecting thousands of sites; users are urged to upgrade to v1.9.13 immediately and review logs for suspicious admin activity.

    11001171
    1.6K followersView on X
  • 🍫ゆきの🌗☕️@wizyig
    Disclosure

    WordPressのphp悪用問題 [TARGET: Everest Forms Pro RCE (CVE-2026-3300)]** https://t.co/Bf9Pp3CnJ2

    Post summary

    A new remote code execution vulnerability (CVE-2026-3300) in Everest Forms Pro for WordPress has been disclosed, detailing the affected product and vulnerability type without evidence of active exploitation, PoC, or patch.

    20000137
    342 followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2025-8088 2 - CVE-2026-4480 3 - CVE-2026-42271 4 - CVE-2026-23111 5 - CVE-2026-3300 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The post lists five trending CVE identifiers without providing any additional details, tooling, or context.

    00020142
    1.7K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Disclosure

    Discover the critical Everest Forms Pro vulnerability (CVE-2026-3300). Learn how attackers exploit eval() and how to protect your WordPress site. #EverestForms #WordPressSecurity #CVE20263300 #InfoSec #Cybersecurity #WebSecurity #Malware https://meterpreter.org/everest-forms-pro-vulnerability/ https://t.co/frVC5iYxI4

    Post summary

    The tweet announces CVE-2026-3300 and directs readers to a link for details on exploiting eval() and protecting WordPress, but provides no concrete proof of concept, exploit code, or patch information.

    00020321
    12.2K followersView on X
  • SoEmailSecurity@Soemailsecurity
    General

    CVE-2026-3300 exploit in Everest Forms Pro plugin lets hackers take over WordPress sites, will you check your site's security before it's too late? Free email scan: http://soemailsecuirty.com #WordPressSecurity #EmailSecurity #Cybersecurity

    Post summary

    The tweet warns that CVE-2026-3300 in the Everest Forms Pro plugin could allow attackers to take over WordPress sites, but it provides no proof of exploitation, technical details, or mitigation information.

    1001046
    64 followersView on X
  • Anavem.com@Anavem_
    Active Exploitation

    CVE-2026-3300: Hackers Exploit Critical Everest Forms Flaw #cve20263300 #everestformspro #wordpressvulnerability https://www.anavem.com/en/news/cybersecurity/cve-2026-3300-hackers-exploit-critical-everest-forms-flaw

    Post summary

    The article reports that hackers are actively exploiting CVE‑2026‑3300, a critical flaw in the Everest Forms Pro plugin for WordPress.

    01010106
    162 followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    CVE-2026-3300 in Everest Forms Pro WordPress plugin actively exploited to create rogue admin accounts via PHP code injection. Attackers using username 'diksimarina' - check your admin users and block IPs 202[.]56[.]2[.]126 and 209[.]146[.]60[.]26. #DFIR_Radar https://t.co/UuMPavYF14

    Post summary

    CVE-2026-3300 is being actively exploited to create rogue admin accounts within Everest Forms Pro via PHP code injection, with attackers using username 'diksimarina' and the listed IP addresses.

    10010344
    1.8K followersView on X
  • SoEmailSecurity@Soemailsecurity
    Disclosure

    CVE-2026-3300 has a CVSS score of 9.8, making it one of the most severe WordPress plugin flaws this year, with 4000 sites at risk, can your site survive an exploit? #WordPressSecurity #CyberSecurity #VulnerabilityManagement

    Post summary

    The post announces CVE‑2026‑3300 as a high‑severity WordPress plugin flaw with a CVSS score of 9.8, highlighting that approximately 4,000 sites are at risk and urging readers to evaluate their vulnerability.

    1001032
    62 followersView on X

Explore more