SECURITYBLEEPING COMPUTER
Critical Everest Forms Pro flaw exploited to take over WordPress sites
Hackers are actively exploiting a critical vulnerability (CVE-2026-3300) in the Everest Forms Pro plugin, allowing them to take complete control of WordPress websites.
Related Signal
Adjacent reporting
- Hackers are actively exploiting a bug in cPanel, used by millions of websites
- Hackers exploit auth bypass flaw in Burst Statistics WordPress plugin
- Hackers are still exploiting the cPanel bug to gain control of thousands of websites
- Hackers Exploit Critical Everest Forms Pro WordPress Plugin Flaw to Take Over Sites
- Critrical cPanel flaw mass-exploited in "Sorry" ransomware attacks
- Critical Kirki flaw exploited to hijack WordPress admin accounts