SECURITYTHE HACKER NEWS
Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
Threat actors are exploiting a critical remote code execution vulnerability (CVE-2026-3300) in Everest Forms Pro, a WordPress plugin with 4,000 active installations, leading to site compromises. The vulnerability affects all versions up to 1.9.12.
Mentioned
Related Signal
Adjacent reporting
- MetInfo CMS CVE-2026-29014 Exploited for Remote Code Execution Attacks
- Microsoft Patches SharePoint RCE Flaw CVE-2026-45659 Across Server Versions
- Ivanti EPMM CVE-2026-6973 RCE Under Active Exploitation Grants Admin-Level Access
- Surge in Bomgar RMM Exploitation Demonstrates Supply Chain Risk
- Researchers Discover Critical GitHub CVE-2026-3854 RCE Flaw Exploitable via Single Git Push
- CISA Adds Exploited Magento RCE Flaw CVE-2026-45247 to KEV Catalog